<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="2.0" pub_date="2019-10-11T04:36:51" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 https://scap.nist.gov/schema/nvd/patch_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 https://scap.nist.gov/schema/nvd/nvd-cve-feed_2.0.xsd http://scap.nist.gov/schema/scap-core/0.1 https://scap.nist.gov/schema/nvd/scap-core_0.1.xsd">
  <entry id="CVE-2003-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0001</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665" name="oval:org.mitre.oval:def:2665"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html" xml:lang="en">20030110 More information regarding Etherleak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104222046632243&amp;w=2" xml:lang="en">20030110 More information regarding Etherleak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a010603-1.txt" xml:lang="en">A010603-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf" xml:lang="en">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/412115" xml:lang="en">VU#412115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-025.html" xml:lang="en">RHSA-2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-088.html" xml:lang="en">RHSA-2003:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305335/30/26420/threaded" xml:lang="en">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/307564/30/26270/threaded" xml:lang="en">20030117 Re: More information regarding Etherleak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1031583" xml:lang="en">1031583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1040185" xml:lang="en">1040185</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:content_management_server:2001</vuln:product>
      <vuln:product>cpe:/a:microsoft:content_management_server:2001:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0002</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:19.100-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=103417794800719&amp;w=2" xml:lang="en">20021007 CSS on Microsoft Content Management Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10318.php" xml:lang="en">mcms-manuallogin-reasontxt-xss (10318)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5922" xml:lang="en">5922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-002" xml:lang="en">MS03-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_2000_terminal_services:-"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services:-:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp1:64-bit"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_2000_terminal_services:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services:-:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp1:64-bit</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0003</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A103" name="oval:org.mitre.oval:def:103"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104394414713415&amp;w=2" xml:lang="en">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104393588232166&amp;w=2" xml:lang="en">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-03.html" xml:lang="en">CA-2003-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/610986" xml:lang="en">VU#610986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6666" xml:lang="en">6666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-001" xml:lang="en">MS03-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11132" xml:lang="en">win-locator-bo(11132)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0004</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:20.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html" xml:lang="en">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104878038418534&amp;w=2" xml:lang="en">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11260.php" xml:lang="en">winxp-windows-redirector-bo(11260)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6778" xml:lang="en">6778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-005" xml:lang="en">MS03-005</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0007</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:21.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6667" xml:lang="en">6667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-003" xml:lang="en">MS03-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11133" xml:lang="en">outlook-v1-certificate-plaintext(11133)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0009</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:21.380-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104636383018686&amp;w=2" xml:lang="en">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-047.shtml" xml:lang="en">N-047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11425.php" xml:lang="en">winme-hsc-hcp-bo(11425)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/489721" xml:lang="en">VU#489721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6966" xml:lang="en">6966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-006" xml:lang="en">MS03-006</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0010</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A134" name="oval:org.mitre.oval:def:134"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A200" name="oval:org.mitre.oval:def:200"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A794" name="oval:org.mitre.oval:def:794"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A795" name="oval:org.mitre.oval:def:795"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html" xml:lang="en">20030319 Windows Scripting Engine issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26" xml:lang="en">20030319 Heap Overflow in Windows Script Engine</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104812108307645&amp;w=2" xml:lang="en">20030319 iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7146" xml:lang="en">7146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-008" xml:lang="en">MS03-008</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:isa_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0011</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:23.240-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7145" xml:lang="en">7145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-009" xml:lang="en">MS03-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0012</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:17.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104154319200399&amp;w=2" xml:lang="en">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-230" xml:lang="en">DSA-230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10971.php" xml:lang="en">bugzilla-mining-world-writable(10971)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-012.html" xml:lang="en">RHSA-2003:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6502" xml:lang="en">6502</vuln:reference>
    </vuln:references>
    <vuln:summary>The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0013</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:18.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104154319200399&amp;w=2" xml:lang="en">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-230" xml:lang="en">DSA-230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10970.php" xml:lang="en">bugzilla-htaccess-database-password(10970)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6501" xml:lang="en">6501</vuln:reference>
    </vuln:references>
    <vuln:summary>The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bmv:bmv:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bmv:bmv:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0014</vuln:cve-id>
    <vuln:published-datetime>2003-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:26.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog" xml:lang="en">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://securityfocus.org/bid/12229" xml:lang="en">12229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012847" xml:lang="en">1012847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-633" xml:lang="en">DSA-633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/18823" xml:lang="en">bmv-symlink(18823)</vuln:reference>
    </vuln:references>
    <vuln:summary>gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.8"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cvs:cvs:1.10.7</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.10.8</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.1</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.1p1</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.2</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.3</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0015</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:18.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-415"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html" xml:lang="en">20030120 Advisory 01/2003: CVS remote vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104333092200589&amp;w=2" xml:lang="en">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104342550612736&amp;w=2" xml:lang="en">20030124 Test program for CVS double-free.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104428571204468&amp;w=2" xml:lang="en">20030202 Exploit for CVS double free() for Linux pserver</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104438807203491&amp;w=2" xml:lang="en">FreeBSD-SA-03:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-013.html" xml:lang="en">RHSA-2003:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/012003.html" xml:lang="en">http://security.e-matters.de/advisories/012003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-02.html" xml:lang="en">CA-2003-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-032.shtml" xml:lang="en">N-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-233" xml:lang="en">DSA-233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/650937" xml:lang="en">VU#650937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009" xml:lang="en">MDKSA-2003:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-012.html" xml:lang="en">RHSA-2003:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6650" xml:lang="en">6650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11108" xml:lang="en">cvs-doublefree-memory-corruption(11108)</vuln:reference>
    </vuln:references>
    <vuln:summary>Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0016</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" xml:lang="en">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apacheweek.com/issues/03-01-24#security" xml:lang="en">http://www.apacheweek.com/issues/03-01-24#security</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/825177" xml:lang="en">VU#825177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/979793" xml:lang="en">VU#979793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6659" xml:lang="en">6659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11124" xml:lang="en">apache-device-name-dos(11124)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11125" xml:lang="en">apache-device-code-execution(11125)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0017</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:23.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" xml:lang="en">http://marc.info/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0018</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11249.php" xml:lang="en">linux-odirect-information-leak(11249)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014" xml:lang="en">MDKSA-2003:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-025.html" xml:lang="en">RHSA-2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6763" xml:lang="en">6763</vuln:reference>
    </vuln:references>
    <vuln:summary>Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:8.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0019</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-044.shtml" xml:lang="en">N-044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11276.php" xml:lang="en">linux-umlnet-gain-privileges(11276)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/134025" xml:lang="en">VU#134025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-056.html" xml:lang="en">RHSA-2003:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6801" xml:lang="en">6801</vuln:reference>
    </vuln:references>
    <vuln:summary>uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0020</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100109" name="oval:org.mitre.oval:def:100109"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A150" name="oval:org.mitre.oval:def:150"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4114" name="oval:org.mitre.oval:def:4114"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046" xml:lang="en">MDKSA-2004:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108369640424244&amp;w=2" xml:lang="en">APPLE-SA-2004-05-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108437852004207&amp;w=2" xml:lang="en">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108731648532365&amp;w=2" xml:lang="en">SSRT4717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-22.xml" xml:lang="en">GLSA-200405-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" xml:lang="en">101555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" xml:lang="en">57628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11412.php" xml:lang="en">apache-esc-seq-injection(11412)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050" xml:lang="en">MDKSA-2003:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-082.html" xml:lang="en">RHSA-2003:082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-083.html" xml:lang="en">RHSA-2003:083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-104.html" xml:lang="en">RHSA-2003:104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-139.html" xml:lang="en">RHSA-2003:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-243.html" xml:lang="en">RHSA-2003:243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-244.html" xml:lang="en">RHSA-2003:244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9930" xml:lang="en">9930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" xml:lang="en">SSA:2004-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0017" xml:lang="en">2004-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0027" xml:lang="en">2004-0027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.8.10</vuln:product>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0021</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:25.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11413.php" xml:lang="en">terminal-emulator-screen-dump(11413)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" xml:lang="en">MDKSA-2003:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6936" xml:lang="en">6936</vuln:reference>
    </vuln:references>
    <vuln:summary>The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0022</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:26.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11413.php" xml:lang="en">terminal-emulator-screen-dump(11413)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" xml:lang="en">MDKSA-2003:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-054.html" xml:lang="en">RHSA-2003:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-055.html" xml:lang="en">RHSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6938" xml:lang="en">6938</vuln:reference>
    </vuln:references>
    <vuln:summary>The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0023</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:28.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11416.php" xml:lang="en">terminal-emulator-menu-modification(11416)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" xml:lang="en">MDKSA-2003:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-054.html" xml:lang="en">RHSA-2003:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-055.html" xml:lang="en">RHSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6947" xml:lang="en">6947</vuln:reference>
    </vuln:references>
    <vuln:summary>The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aterm:aterm:0.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aterm:aterm:0.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0024</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:29.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11416.php" xml:lang="en">terminal-emulator-menu-modification(11416)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6949" xml:lang="en">6949</vuln:reference>
    </vuln:references>
    <vuln:summary>The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:horde:imp:2.2</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.1</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.2</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.3</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.4</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.5</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.6</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.7</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0025</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:30.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104204786206563&amp;w=2" xml:lang="en">20030108 IMP 2.x SQL injection vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-229" xml:lang="en">DSA-229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/306268" xml:lang="en">20030108 Re: IMP 2.x SQL injection vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6559" xml:lang="en">6559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005904" xml:lang="en">1005904</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:dhcpd:3.0</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0026</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html" xml:lang="en">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562" xml:lang="en">CLA-2003:562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-01.html" xml:lang="en">CA-2003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-031.shtml" xml:lang="en">N-031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-231" xml:lang="en">DSA-231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/284857" xml:lang="en">VU#284857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007" xml:lang="en">MDKSA-2003:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html" xml:lang="en">OpenPKG-SA-2003.002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-011.html" xml:lang="en">RHSA-2003:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6627" xml:lang="en">6627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005924" xml:lang="en">1005924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.suse.com/de/security/2003_006_dhcp.html" xml:lang="en">SuSE-SA:2003:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11073" xml:lang="en">dhcpd-minires-multiple-bo(11073)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0027</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A120" name="oval:org.mitre.oval:def:120"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A195" name="oval:org.mitre.oval:def:195"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2592" name="oval:org.mitre.oval:def:2592"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104326556329850&amp;w=2" xml:lang="en">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104" xml:lang="en">50104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.entercept.com/news/uspr/01-22-03.asp" xml:lang="en">http://www.entercept.com/news/uspr/01-22-03.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/850785" xml:lang="en">VU#850785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6665" xml:lang="en">6665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11129" xml:lang="en">solaris-kcms-directory-traversal(11129)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.0e"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_700:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_800:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:glibc:2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1.1</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1.3</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.2</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.3</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.4</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.5</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.3</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.3.1</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.3.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.5</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.7</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.2</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.3</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.4</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.4a</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.1.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.1.1a</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.2</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.2a</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.2b</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.3</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.4</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.5</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.6</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.3</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.3.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.3.2</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:6.0</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:6.0e</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:6.1</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:7.0</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:8.0</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:8.3</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.0</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.0.2.5</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.2</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_700:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_800:10.20</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0028</vuln:cve-id>
    <vuln:published-datetime>2003-03-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A230" name="oval:org.mitre.oval:def:230"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc" xml:lang="en">NetBSD-SA2003-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html" xml:lang="en">20030319 EEYE: XDR Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104810574423662&amp;w=2" xml:lang="en">20030319 EEYE: XDR Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104811415301340&amp;w=2" xml:lang="en">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104860855114117&amp;w=2" xml:lang="en">20030325 GLSA:  glibc (200303-22)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104878237121402&amp;w=2" xml:lang="en">2003-0014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105362148313082&amp;w=2" xml:lang="en">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-10.html" xml:lang="en">CA-2003-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-272" xml:lang="en">DSA-272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-282" xml:lang="en">DSA-282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20030318.html" xml:lang="en">AD20030318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/516825" xml:lang="en">VU#516825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html" xml:lang="en">ESA-20030321-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037" xml:lang="en">MDKSA-2003:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_027_glibc.html" xml:lang="en">SuSE-SA:2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-089.html" xml:lang="en">RHSA-2003:089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315638/30/25430/threaded" xml:lang="en">20030319 RE: EEYE: XDR Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316931/30/25250/threaded" xml:lang="en">20030331 GLSA: dietlibc (200303-29)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://security.netapp.com/advisory/ntap-20150122-0002/" xml:lang="en">https://security.netapp.com/advisory/ntap-20150122-0002/</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:protegrity:secure.data:2.2.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:protegrity:secure.data:2.2.3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:protegrity:secure.data:2.2.3.7</vuln:product>
      <vuln:product>cpe:/a:protegrity:secure.data:2.2.3.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0030</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:34.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104758650516677&amp;w=2" xml:lang="en">20030313 Protegrity buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/247545" xml:lang="en">VU#247545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7083" xml:lang="en">7083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7084" xml:lang="en">7084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7085" xml:lang="en">7085</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.1_r4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.1_r4</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.2</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.3</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5_.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0031</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:36.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" xml:lang="en">CLA-2003:567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104162752401212&amp;w=2" xml:lang="en">20030103 Multiple libmcrypt vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104188513728573&amp;w=2" xml:lang="en">20030105 GLSA:  libmcrypt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-228" xml:lang="en">DSA-228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6510" xml:lang="en">6510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006181" xml:lang="en">1006181</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.1_r4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.1_r4</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.2</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.3</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5_.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0032</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:37.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" xml:lang="en">CLA-2003:567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104162752401212&amp;w=2" xml:lang="en">20030103 Multiple libmcrypt vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104188513728573&amp;w=2" xml:lang="en">20030105 GLSA:  libmcrypt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-228" xml:lang="en">DSA-228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10988.php" xml:lang="en">libmcrypt-libtool-memory-leak(10988)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6512" xml:lang="en">6512</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snort:snort:1.8.0</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.1</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.2</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.3</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.4</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.5</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.6</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.7</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0033</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:38.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104673386226064&amp;w=2" xml:lang="en">20030303 Snort RPC Vulnerability (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104716001503409&amp;w=2" xml:lang="en">GLSA-200303-6.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105154530427824&amp;w=2" xml:lang="en">GLSA-200304-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-13.html" xml:lang="en">CA-2003-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-297" xml:lang="en">DSA-297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951" xml:lang="en">20030303 Snort RPC Preprocessing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10956.php" xml:lang="en">snort-rpc-fragment-bo(10956)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/916785" xml:lang="en">VU#916785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html" xml:lang="en">ESA-20030307-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029" xml:lang="en">MDKSA-2003:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6963" xml:lang="en">6963</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.32"/>
        <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.33"/>
        <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.52"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.32</vuln:product>
      <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.33</vuln:product>
      <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.52</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0034</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:24.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.21.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" xml:lang="en">MDKSA-2003:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6656" xml:lang="en">6656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005959" xml:lang="en">1005959</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:robert_krawitz:escputil:1.15.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:robert_krawitz:escputil:1.15.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0035</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:19.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.21.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" xml:lang="en">MDKSA-2003:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/307608/30/26270/threaded" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6658" xml:lang="en">6658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005959" xml:lang="en">1005959</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rildo_pragana:ml85p"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rildo_pragana:ml85p</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0036</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:19.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.21.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" xml:lang="en">MDKSA-2003:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/307608/30/26270/threaded" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005959" xml:lang="en">1005959</vuln:reference>
    </vuln:references>
    <vuln:summary>ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</vuln:summary>
  </entry>
  <entry id="CVE-2003-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:noffle:noffle:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:noffle:noffle:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0037</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-244" xml:lang="en">DSA-244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6695" xml:lang="en">6695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11181" xml:lang="en">noffle-multiple-bo(11181)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0038</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104342745916111" xml:lang="en">20030124 Mailman: cross-site scripting bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt" xml:lang="en">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-436" xml:lang="en">DSA-436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6677" xml:lang="en">6677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005987" xml:lang="en">1005987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11152" xml:lang="en">mailman-email-variable-xss(11152)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc10"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc10</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc8</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0039</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://cc.turbolinux.com/security/TLSA-2003-26.txt" xml:lang="en">TLSA-2003-26</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616" xml:lang="en">CLSA-2003:616</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104310927813830&amp;w=2" xml:lang="en">20030115 DoS against DHCP infrastructure with isc dhcrelay</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-245" xml:lang="en">DSA-245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/149953" xml:lang="en">VU#149953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html" xml:lang="en">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-034.html" xml:lang="en">RHSA-2003:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6628" xml:lang="en">6628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11187" xml:lang="en">dhcp-dhcrelay-dos(11187)</vuln:reference>
    </vuln:references>
    <vuln:summary>ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:double_precision_incorporated:courier_mta:0.37.3"/>
        <cpe-lang:fact-ref name="cpe:/a:inter7:courier-imap:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:double_precision_incorporated:courier_mta:0.37.3</vuln:product>
      <vuln:product>cpe:/a:inter7:courier-imap:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0040</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-247" xml:lang="en">DSA-247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6738" xml:lang="en">6738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11213" xml:lang="en">courierimap-authmysqllib-sql-injection(11213)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos_ftp_client"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos_ftp_client</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:6.2::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.0::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2::ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0041</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:27.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html" xml:lang="en">20030128 MIT Kerberos FTP client remote shell commands execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021" xml:lang="en">MDKSA-2003:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-020.html" xml:lang="en">RHSA-2003:020</vuln:reference>
    </vuln:references>
    <vuln:summary>Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0042</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104394568616290&amp;w=2" xml:lang="en">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-060.shtml" xml:lang="en">N-060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-246" xml:lang="en">DSA-246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5111" xml:lang="en">HPSBUX0303-249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6721" xml:lang="en">6721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11194" xml:lang="en">tomcat-null-directory-listing(11194)</vuln:reference>
    </vuln:references>
    <vuln:summary>Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0043</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-060.shtml" xml:lang="en">N-060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-246" xml:lang="en">DSA-246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5111" xml:lang="en">HPSBUX0303-249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6722" xml:lang="en">6722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11195" xml:lang="en">tomcat-webxml-read-files(11195)</vuln:reference>
    </vuln:references>
    <vuln:summary>Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0044</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-060.shtml" xml:lang="en">N-060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-246" xml:lang="en">DSA-246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5111" xml:lang="en">HPSBUX0303-249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6720" xml:lang="en">6720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11196" xml:lang="en">tomcat-web-app-xss(11196)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0045</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12102" xml:lang="en">jakarta-tomcat-msdos-dos(12102)</vuln:reference>
    </vuln:references>
    <vuln:summary>Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0046</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:43.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104386492422014&amp;w=2" xml:lang="en">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.celestialsoftware.net/telnet/beta_software.html" xml:lang="en">http://www.celestialsoftware.net/telnet/beta_software.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.28.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6725" xml:lang="en">6725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006013" xml:lang="en">1006013</vuln:reference>
    </vuln:references>
    <vuln:summary>AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:entunnel:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securecrt:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securecrt:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securefx:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securefx:2.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:van_dyke_technologies:entunnel:1.0.2</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securecrt:3.4.7</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securecrt:4.0.2</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securefx:2.0.4</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securefx:2.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0047</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:45.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104386492422014&amp;w=2" xml:lang="en">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.28.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6726" xml:lang="en">6726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6727" xml:lang="en">6727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6728" xml:lang="en">6728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006010" xml:lang="en">1006010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006011" xml:lang="en">1006011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006012" xml:lang="en">1006012</vuln:reference>
    </vuln:references>
    <vuln:summary>SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.48"/>
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.49"/>
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:putty:putty:0.48</vuln:product>
      <vuln:product>cpe:/a:putty:putty:0.49</vuln:product>
      <vuln:product>cpe:/a:putty:putty:0.53</vuln:product>
      <vuln:product>cpe:/a:putty:putty:0.53b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0048</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:46.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104386492422014&amp;w=2" xml:lang="en">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.28.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6724" xml:lang="en">6724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006014" xml:lang="en">1006014</vuln:reference>
    </vuln:references>
    <vuln:summary>PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0049</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006107" xml:lang="en">1006107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11333.php" xml:lang="en">macos-afp-unauthorized-access(11333)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6860" xml:lang="en">6860</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0050</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:47.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11401.php" xml:lang="en">quicktime-darwin-command-execution(11401)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6954" xml:lang="en">6954</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0051</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:48.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11402.php" xml:lang="en">quicktime-darwin-path-disclosure(11402)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6956" xml:lang="en">6956</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0052</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:49.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11403.php" xml:lang="en">quicktime-darwin-directory-disclosure(11403)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6955" xml:lang="en">6955</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0053</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:51.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11404.php" xml:lang="en">quicktime-darwin-parsexml-xss(11404)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6958" xml:lang="en">6958</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0054</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:52.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11405.php" xml:lang="en">quicktime-darwin-describe-xss(11405)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6960" xml:lang="en">6960</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_darwin_mp3_broadcaster"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_darwin_mp3_broadcaster</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0055</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:53.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11406.php" xml:lang="en">quicktime-darwin-mp3-bo(11406)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6957" xml:lang="en">6957</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:slocate:slocate:2.5</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0056</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:04.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11369" name="oval:org.mitre.oval:def:11369"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt" xml:lang="en">CSSA-2003-009.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104342864418213&amp;w=2" xml:lang="en">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104348607205691&amp;w=2" xml:lang="en">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104428624705363&amp;w=2" xml:lang="en">20030202 GLSA:  slocate</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-041.html" xml:lang="en">RHSA-2004:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-252" xml:lang="en">DSA-252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015" xml:lang="en">MDKSA-2003:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://www.net-security.org/advisory.php?id=2010" xml:lang="en">CLA-2003:643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.usg.org.uk/advisories/2003.001.txt" xml:lang="en">http://www.usg.org.uk/advisories/2003.001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.0b25"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hypermail:hypermail:2.0b25</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.1</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.2</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.3</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.4</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.5</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1_.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0057</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html" xml:lang="en">20030126 Hypermail buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104369136703903&amp;w=2" xml:lang="en">20030127 Hypermail buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-248" xml:lang="en">DSA-248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6689" xml:lang="en">6689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6690" xml:lang="en">6690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11157" xml:lang="en">hypermail-mail-attachment-bo(11157)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11158" xml:lang="en">hypermail-long-hostname-bo(11158)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:enterprise_authentication_mechanism:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:sun:enterprise_authentication_mechanism:1.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0058</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1110" name="oval:org.mitre.oval:def:1110"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" xml:lang="en">CLSA-2003:639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142" xml:lang="en">50142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/661243" xml:lang="en">VU#661243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" xml:lang="en">MDKSA-2003:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-168.html" xml:lang="en">RHSA-2003:168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6683" xml:lang="en">6683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/10099" xml:lang="en">kerberos-kdc-null-pointer-dos(10099)</vuln:reference>
    </vuln:references>
    <vuln:summary>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0059</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:13.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" xml:lang="en">CLSA-2003:639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/684563" xml:lang="en">VU#684563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" xml:lang="en">MDKSA-2003:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-168.html" xml:lang="en">RHSA-2003:168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6714" xml:lang="en">6714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11188" xml:lang="en">kerberos-kdc-user-spoofing(11188)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0060</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" xml:lang="en">CLSA-2003:639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/787523" xml:lang="en">VU#787523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6712" xml:lang="en">6712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11189" xml:lang="en">kerberos-kdc-format-string(11189)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0061</vuln:cve-id>
    <vuln:published-datetime>2002-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:21.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-25T11:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eset_software:nod32_antivirus:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:eset_software:nod32_antivirus:1.0.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eset_software:nod32_antivirus:1.0.11</vuln:product>
      <vuln:product>cpe:/a:eset_software:nod32_antivirus:1.0.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0062</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:57.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104490777824360&amp;w=2" xml:lang="en">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/02.10.03.txt" xml:lang="en">http://www.idefense.com/advisory/02.10.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11282.php" xml:lang="en">nod32-pathname-bo(11282)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6803" xml:lang="en">6803</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0063</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:28:58.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-380" xml:lang="en">DSA-380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-064.html" xml:lang="en">RHSA-2003:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-065.html" xml:lang="en">RHSA-2003:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-066.html" xml:lang="en">RHSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-067.html" xml:lang="en">RHSA-2003:067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6940" xml:lang="en">6940</vuln:reference>
    </vuln:references>
    <vuln:summary>The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0064</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6236" xml:lang="en">HPSBUX0401-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6942" xml:lang="en">6942</vuln:reference>
    </vuln:references>
    <vuln:summary>The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:national_university_of_singapore:uxterm:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:national_university_of_singapore:uxterm:2.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:national_university_of_singapore:uxterm:2.3</vuln:product>
      <vuln:product>cpe:/a:national_university_of_singapore:uxterm:2.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0065</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:01.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6945" xml:lang="en">6945</vuln:reference>
    </vuln:references>
    <vuln:summary>The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0066</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:02.690-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003" xml:lang="en">MDKSA-2003:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-054.html" xml:lang="en">RHSA-2003:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-055.html" xml:lang="en">RHSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5137" xml:lang="en">200303-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6953" xml:lang="en">6953</vuln:reference>
    </vuln:references>
    <vuln:summary>The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aterm:aterm:0.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aterm:aterm:0.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0067</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:03.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:summary>The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.8.10</vuln:product>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0068</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:05.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-496" xml:lang="en">DSA-496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" xml:lang="en">MDKSA-2003:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10237" xml:lang="en">10237</vuln:reference>
    </vuln:references>
    <vuln:summary>The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:putty:putty:0.53</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0069</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:06.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:summary>The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.11.21"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.12.2"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.14.2"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.15.0"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.16.14"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.17.4"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.20.5"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.22.5"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.24.3"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.25.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gnome-terminal:2.0</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome-terminal:2.2</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.11.21</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.12.2</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.14.2</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.15.0</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.16.14</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.17.4</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.20.5</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.22.5</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.24.3</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.25.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0070</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:07.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://seclists.org/lists/bugtraq/2003/Mar/0010.html" xml:lang="en">GLSA-200303-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-053.html" xml:lang="en">RHSA-2003:053</vuln:reference>
    </vuln:references>
    <vuln:summary>VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0071</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:08.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-380" xml:lang="en">DSA-380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11415.php" xml:lang="en">terminal-emulator-dec-udk(11415)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-064.html" xml:lang="en">RHSA-2003:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-065.html" xml:lang="en">RHSA-2003:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-066.html" xml:lang="en">RHSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-067.html" xml:lang="en">RHSA-2003:067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6950" xml:lang="en">6950</vuln:reference>
    </vuln:references>
    <vuln:summary>The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.2.2.beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:1.0</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:1.2.2.beta1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.5</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.7</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.3:alpha1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.0.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0072</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:19.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" xml:lang="en">54042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7184" xml:lang="en">7184</vuln:reference>
    </vuln:references>
    <vuln:summary>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.31"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.36"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.41"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.47"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.52"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:mysql:3.23.31</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.36</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.41</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.47</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.52</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0073</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-07T12:41:09.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A436" name="oval:org.mitre.oval:def:436"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" xml:lang="en">CLA-2003:743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104385719107879&amp;w=2" xml:lang="en">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-303" xml:lang="en">DSA-303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11199.php" xml:lang="en">mysql-mysqlchangeuser-doublefree-dos(11199)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html" xml:lang="en">ESA-20030220-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013" xml:lang="en">MDKSA-2003:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mysql.com/doc/en/News-3.23.55.html" xml:lang="en">http://www.mysql.com/doc/en/News-3.23.55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-093.html" xml:lang="en">RHSA-2003:093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-094.html" xml:lang="en">RHSA-2003:094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-166.html" xml:lang="en">RHSA-2003:166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6718" xml:lang="en">6718</vuln:reference>
    </vuln:references>
    <vuln:summary>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plptools:plptools:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plptools:plptools:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0074</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:11.800-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104385772908969&amp;w=2" xml:lang="en">20030129 Local root vuln in SuSE 8.0 plptools package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104386699725019&amp;w=2" xml:lang="en">20030129 Re: Local root vuln in SuSE 8.0 plptools package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11193.php" xml:lang="en">plptools-plpnsfd-format-string(11193)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6715" xml:lang="en">6715</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.92.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.93.10"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.92.7</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.93.10</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.0</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.1</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0075</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:13.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104428700106672&amp;w=2" xml:lang="en">20030202 Bladeenc 0.94.2 code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104446346127432&amp;w=2" xml:lang="en">GLSA-200302-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11227.php" xml:lang="en">bladeenc-myfseek-code-execution(11227)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pivx.com/luigi/adv/blade942-adv.txt" xml:lang="en">http://www.pivx.com/luigi/adv/blade942-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6745" xml:lang="en">6745</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dcgui:dcgui:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dcgui:dcgui:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qt-dcgui:qt-dcgui:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qt-dcgui:qt-dcgui:0.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dcgui:dcgui:0.2</vuln:product>
      <vuln:product>cpe:/a:dcgui:dcgui:0.2.1</vuln:product>
      <vuln:product>cpe:/a:qt-dcgui:qt-dcgui:0.2</vuln:product>
      <vuln:product>cpe:/a:qt-dcgui:qt-dcgui:0.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0076</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:14.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html" xml:lang="en">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104437720116243&amp;w=2" xml:lang="en">20030204 GLSA:  qt-dcgui</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11246.php" xml:lang="en">qtdcgui-directory-download-files(11246)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hanterm:hanterm-xf:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hanterm:hanterm-xf:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0077</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:15.410-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-070.html" xml:lang="en">RHSA-2003:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-071.html" xml:lang="en">RHSA-2003:071</vuln:reference>
    </vuln:references>
    <vuln:summary>The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0078</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:16.643-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc" xml:lang="en">NetBSD-SA2003-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" xml:lang="en">20030501-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570" xml:lang="en">CLSA-2003:570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104567627211904&amp;w=2" xml:lang="en">20030219 OpenSSL 0.9.7a and 0.9.6i released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104568426824439&amp;w=2" xml:lang="en">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104577183206905&amp;w=2" xml:lang="en">GLSA-200302-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-051.shtml" xml:lang="en">N-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-253" xml:lang="en">DSA-253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11369.php" xml:lang="en">ssl-cbc-information-leak(11369)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html" xml:lang="en">ESA-20030220-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020" xml:lang="en">MDKSA-2003:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20030219.txt" xml:lang="en">http://www.openssl.org/news/secadv_20030219.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-062.html" xml:lang="en">RHSA-2003:062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-063.html" xml:lang="en">RHSA-2003:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-082.html" xml:lang="en">RHSA-2003:082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-104.html" xml:lang="en">RHSA-2003:104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-205.html" xml:lang="en">RHSA-2003:205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6884" xml:lang="en">6884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2003/0005" xml:lang="en">2003-0005</vuln:reference>
    </vuln:references>
    <vuln:summary>ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hanterm:hanterm-xf:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hanterm:hanterm-xf:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0079</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:18.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11415.php" xml:lang="en">terminal-emulator-dec-udk(11415)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-070.html" xml:lang="en">RHSA-2003:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-071.html" xml:lang="en">RHSA-2003:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6944" xml:lang="en">6944</vuln:reference>
    </vuln:references>
    <vuln:summary>The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-lokkit:0.50_21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gnome-lokkit:0.50_21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0080</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-072.html" xml:lang="en">RHSA-2003:072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7128" xml:lang="en">7128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11552" xml:lang="en">gnomelokkit-forward-bypass-firewall(11552)</vuln:reference>
    </vuln:references>
    <vuln:summary>The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.0</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0081</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A54" name="oval:org.mitre.oval:def:54"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627" xml:lang="en">CLSA-2003:627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051" xml:lang="en">MDKSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html" xml:lang="en">20030308 Ethereal format string bug, yet still ethereal much better than windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-258" xml:lang="en">DSA-258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00008.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00008.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.guninski.com/etherre.html" xml:lang="en">http://www.guninski.com/etherre.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html" xml:lang="en">GLSA-200303-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" xml:lang="en">SuSE-SA:2003:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-076.html" xml:lang="en">RHSA-2003:076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7049" xml:lang="en">7049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11497" xml:lang="en">ethereal-socks-format-string(11497)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.2.2.beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:1.0</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:1.2.2.beta1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.5</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.7</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.3:alpha1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.0.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0082</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:20.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A244" name="oval:org.mitre.oval:def:244"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2536" name="oval:org.mitre.oval:def:2536"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4430" name="oval:org.mitre.oval:def:4430"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" xml:lang="en">54042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7185" xml:lang="en">7185</vuln:reference>
    </vuln:references>
    <vuln:summary>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0083</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:04.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A151" name="oval:org.mitre.oval:def:151"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25" xml:lang="en">http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH" xml:lang="en">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108024081011678&amp;w=2" xml:lang="en">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108034113406858&amp;w=2" xml:lang="en">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-139.html" xml:lang="en">RHSA-2003:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_any:mod_auth_any:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_auth_any:mod_auth_any:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0084</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-114.html" xml:lang="en">RHSA-2003:114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-090.shtml" xml:lang="en">N-090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.itlab.musc.edu/webNIS/mod_auth_any.html" xml:lang="en">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-113.html" xml:lang="en">RHSA-2003:113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7448" xml:lang="en">7448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11893" xml:lang="en">modauthany-command-execution(11893)</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.05</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.06</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.07</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.01</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0085</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:21.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A552" name="oval:org.mitre.oval:def:552"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" xml:lang="en">20030302-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792646416629&amp;w=2" xml:lang="en">20030317 GLSA:  samba (200303-11)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792723017768&amp;w=2" xml:lang="en">20030317 Security Bugfix for Samba - Samba 2.2.8 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104801012929374&amp;w=2" xml:lang="en">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-262" xml:lang="en">DSA-262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" xml:lang="en">GLSA-200303-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/298233" xml:lang="en">VU#298233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" xml:lang="en">MDKSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_016_samba.html" xml:lang="en">SuSE-SA:2003:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-095.html" xml:lang="en">RHSA-2003:095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-096.html" xml:lang="en">RHSA-2003:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317145/30/25220/threaded" xml:lang="en">IMNX-2003-7+-003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7106" xml:lang="en">7106</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0086</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:22.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A554" name="oval:org.mitre.oval:def:554"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" xml:lang="en">20030302-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792646416629&amp;w=2" xml:lang="en">20030317 GLSA:  samba (200303-11)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104801012929374&amp;w=2" xml:lang="en">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-262" xml:lang="en">DSA-262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" xml:lang="en">GLSA-200303-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" xml:lang="en">MDKSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_016_samba.html" xml:lang="en">SuSE-SA:2003:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-095.html" xml:lang="en">RHSA-2003:095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-096.html" xml:lang="en">RHSA-2003:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7107" xml:lang="en">7107</vuln:reference>
    </vuln:references>
    <vuln:summary>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:national_language_support:libim"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:national_language_support:libim</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0087</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html" xml:lang="en">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104508375107938&amp;w=2" xml:lang="en">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104508833214691&amp;w=2" xml:lang="en">20030212 libIM.a buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/02.12.03.txt" xml:lang="en">http://www.idefense.com/advisory/02.12.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6840" xml:lang="en">6840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only" xml:lang="en">IY40307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only" xml:lang="en">IY40317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only" xml:lang="en">IY40320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11309" xml:lang="en">aix-aixterm-libim-bo(11309)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0088</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:48.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a021403-1.txt" xml:lang="en">A021403-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11332.php" xml:lang="en">macos-trublueenvironment-gain-privileges(11332)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6859" xml:lang="en">6859</vuln:reference>
    </vuln:references>
    <vuln:summary>TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0089</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5466" name="oval:org.mitre.oval:def:5466"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0038.html" xml:lang="en">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106873965001431&amp;w=2" xml:lang="en">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6030" xml:lang="en">HPSBUX0311-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8986" xml:lang="en">8986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13623" xml:lang="en">hp-sd-utilities-bo(13623)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0090">
    <vuln:cve-id>CVE-2003-0090</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:53.633-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2000-0844.  Reason: This candidate is a duplicate of CVE-2000-0844.  Notes: All CVE users should reference CVE-2000-0844 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0091</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4383" name="oval:org.mitre.oval:def:4383"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html" xml:lang="en">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt" xml:lang="en">http://packetstormsecurity.org/0304-advisories/sa2003-02.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1" xml:lang="en">52443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-068.shtml" xml:lang="en">N-068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nsfocus.com/english/homepage/sa2003-02.htm" xml:lang="en">http://www.nsfocus.com/english/homepage/sa2003-02.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316957/30/25250/threaded" xml:lang="en">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0092</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1905" name="oval:org.mitre.oval:def:1905"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html" xml:lang="en">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1" xml:lang="en">52388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316948/30/25250/threaded" xml:lang="en">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7240" xml:lang="en">7240</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4a6"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.4</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.4a6</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0093</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-261" xml:lang="en">DSA-261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" xml:lang="en">MDKSA-2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-032.html" xml:lang="en">RHSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-033.html" xml:lang="en">RHSA-2003:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-214.html" xml:lang="en">RHSA-2003:214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11324" xml:lang="en">tcpdump-radius-decoder-dos(11324)</vuln:reference>
    </vuln:references>
    <vuln:summary>The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11n"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11u"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11n</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11u</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0094</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016" xml:lang="en">MDKSA-2003:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6855" xml:lang="en">6855</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11318" xml:lang="en">utillinux-mcookie-cookie-predictable(11318)</vuln:reference>
    </vuln:references>
    <vuln:summary>A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0095</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:25.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104549693426042&amp;w=2" xml:lang="en">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-05.html" xml:lang="en">CA-2003-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-046.shtml" xml:lang="en">N-046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11328.php" xml:lang="en">oracle-username-bo(11328)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/953746" xml:lang="en">VU#953746</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6849" xml:lang="en">6849</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0096</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:27.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html" xml:lang="en">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html" xml:lang="en">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html" xml:lang="en">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104549743326864&amp;w=2" xml:lang="en">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104549782327321&amp;w=2" xml:lang="en">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550346303295&amp;w=2" xml:lang="en">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-05.html" xml:lang="en">CA-2003-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-046.shtml" xml:lang="en">N-046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11325.php" xml:lang="en">oracle-bfilename-directory-bo(11325)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11326.php" xml:lang="en">oracle-tzoffset-bo(11326)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11327.php" xml:lang="en">oracle-totimestamptz-bo(11327)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/663786" xml:lang="en">VU#663786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/743954" xml:lang="en">VU#743954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/840666" xml:lang="en">VU#840666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora-bfilebo.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora-bfilebo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora-tzofstbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6847" xml:lang="en">6847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6848" xml:lang="en">6848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6850" xml:lang="en">6850</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0097</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550977011668&amp;w=2" xml:lang="en">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104567042700840&amp;w=2" xml:lang="en">GLSA-200302-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104567137502557&amp;w=2" xml:lang="en">GLSA-200302-09.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11343.php" xml:lang="en">php-cgi-sapi-access(11343)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6875" xml:lang="en">6875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.slackware.com/changelog/current.php?cpu=i386" xml:lang="en">http://www.slackware.com/changelog/current.php?cpu=i386</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:0.3.91_5"/>
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:3.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:3.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:3.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:3.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:3.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apcupsd:apcupsd:3.10.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apcupsd:apcupsd:0.3.91_5</vuln:product>
      <vuln:product>cpe:/a:apcupsd:apcupsd:3.8.5</vuln:product>
      <vuln:product>cpe:/a:apcupsd:apcupsd:3.10.0</vuln:product>
      <vuln:product>cpe:/a:apcupsd:apcupsd:3.10.1</vuln:product>
      <vuln:product>cpe:/a:apcupsd:apcupsd:3.10.2</vuln:product>
      <vuln:product>cpe:/a:apcupsd:apcupsd:3.10.3</vuln:product>
      <vuln:product>cpe:/a:apcupsd:apcupsd:3.10.4</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0098</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-09-26T11:59:18.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-09-25T12:53:34.317-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" xml:lang="en">CSSA-2003-015.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6" xml:lang="en">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt" xml:lang="en">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006108" xml:lang="en">1006108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137900" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-277" xml:lang="en">DSA-277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11334.php" xml:lang="en">apcupsd-logevent-format-string(11334)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" xml:lang="en">MDKSA-2003:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" xml:lang="en">SuSE-SA:2003:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6828" xml:lang="en">6828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7200" xml:lang="en">7200</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apc:apcupsd:3.8.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0099</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:55.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" xml:lang="en">CSSA-2003-015.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006108" xml:lang="en">1006108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137892" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137900" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-277" xml:lang="en">DSA-277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11491.php" xml:lang="en">apcupsd-vsprintf-multiple-bo(11491)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" xml:lang="en">MDKSA-2003:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" xml:lang="en">SuSE-SA:2003:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7200" xml:lang="en">7200</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%287%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%287%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%289%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29cc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2820%29aa4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2824a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2824b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2828a%29ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2828a%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29ca2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29cc2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29cc4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1cc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29f"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29f1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29xaf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288.9%29sa6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2810%29bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2811b%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2817%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2819%29gs0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2819a%29gs6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2823a%29bc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826%29p2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2gs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2sa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2wa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2wa4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29ed"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%282%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%287%29db1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%288%29db2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811%29b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811b%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3ha"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3ma"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3na"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3wa4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29w"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283d%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xe1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xm1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29t1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc2b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc3b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xk2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xn1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29yb4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.1%29xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.2%29xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.3%29wc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.4%29wc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%286b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29db2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29dc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29s1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xe2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xf1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xk3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287.4%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288%29s1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288.0.2%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288.3%29sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29s8"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29s7"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811%29s6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811%29st4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2812%29s3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2812a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29s6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29wt6%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29s7"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29st3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29w5%2820%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29s8"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29sc3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29st1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29w5%2821%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816.06%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29st1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29st5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29st1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0w5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xw"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:11.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%287%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%287%29ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%289%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2817%29cc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2817%29ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2820%29aa4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2824a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2824b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2828a%29ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2828a%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2836%29ca2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2836%29cc2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2836%29cc4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1cc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29f</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29f1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29xaf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288.9%29sa6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%289%29p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%289%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2810%29bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2811b%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2817%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2819%29gs0.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2819a%29gs6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2823a%29bc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2826%29p2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2826a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2826b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2f</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2gs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2sa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2wa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2wa4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29ed</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%282%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%287%29db1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%288%29db2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811%29b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811b%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3ha</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3ma</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3na</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3wa4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29w</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%283%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%283d%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xe1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xm1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29t1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc2b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc3b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xk2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xn1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29yb4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.1%29xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.2%29xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.3%29wc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.4%29wc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%286b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29db2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29dc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29s1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xe2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xf1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xk3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287.4%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288%29s1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288.0.2%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288.3%29sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289%29s8</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29s7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2811%29s6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2811%29st4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2811a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2812%29s3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2812a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813%29s6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813%29wt6%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29s7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29st3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29w5%2820%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29s8</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29sc3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29st1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29w5%2821%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816.06%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29st1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29st5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29st1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0dc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0w5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xw</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0100</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:29.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104576100719090&amp;w=2" xml:lang="en">20030220 Cisco IOS OSPF exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104587206702715&amp;w=2" xml:lang="en">20030221 Re: Cisco IOS OSPF exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11373.php" xml:lang="en">cisco-ios-ospf-bo(11373)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6895" xml:lang="en">6895</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:engardelinux:guardian_digital_webtool:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.94"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.96"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.97"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.98"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.50"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.60"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:engardelinux:guardian_digital_webtool:1.2</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.4</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.5</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.6</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.7</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.8</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.9</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.91</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.92</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.93</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.94</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.95</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.96</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.97</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.98</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.99</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.50</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.60</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0101</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:30.850-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I" xml:lang="en">20030602-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html" xml:lang="en">HPSBUX0303-250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html" xml:lang="en">ESA-20030225-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104610245624895&amp;w=2" xml:lang="en">20030224 Webmin 1.050 - 1.060 remote exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104610300325629&amp;w=2" xml:lang="en">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104610336226274&amp;w=2" xml:lang="en">20030224 GLSA:  usermin (200302-14)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=webmin-announce&amp;m=104587858408101&amp;w=2" xml:lang="en">http://marc.info/?l=webmin-announce&amp;m=104587858408101&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-058.shtml" xml:lang="en">N-058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-319" xml:lang="en">DSA-319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11390.php" xml:lang="en">webmin-usermin-root-access(11390)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lac.co.jp/security/english/snsadv_e/62_e.html" xml:lang="en">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html" xml:lang="en">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025" xml:lang="en">MDKSA-2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6915" xml:lang="en">6915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006160" xml:lang="en">1006160</vuln:reference>
    </vuln:references>
    <vuln:summary>miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.30"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.33"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.34"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.35"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.36"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.37"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.39"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:file:file:3.28</vuln:product>
      <vuln:product>cpe:/a:file:file:3.30</vuln:product>
      <vuln:product>cpe:/a:file:file:3.32</vuln:product>
      <vuln:product>cpe:/a:file:file:3.33</vuln:product>
      <vuln:product>cpe:/a:file:file:3.34</vuln:product>
      <vuln:product>cpe:/a:file:file:3.35</vuln:product>
      <vuln:product>cpe:/a:file:file:3.36</vuln:product>
      <vuln:product>cpe:/a:file:file:3.37</vuln:product>
      <vuln:product>cpe:/a:file:file:3.39</vuln:product>
      <vuln:product>cpe:/a:file:file:3.40</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0102</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:19.100-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc" xml:lang="en">NetBSD-SA2003-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/34908/" xml:lang="en">IMNX-2003-7+-012-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104680706201721&amp;w=2" xml:lang="en">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-260" xml:lang="en">DSA-260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/03.04.03.txt" xml:lang="en">http://www.idefense.com/advisory/03.04.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/611865" xml:lang="en">VU#611865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030" xml:lang="en">MDKSA-2003:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_017_file.html" xml:lang="en">SuSE-SA:2003:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-086.html" xml:lang="en">RHSA-2003:086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-087.html" xml:lang="en">RHSA-2003:087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7008" xml:lang="en">7008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11469" xml:lang="en">file-afctr-read-bo(11469)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:nokia:6210_handset:5.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:nokia:6210_handset:5.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0103</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:29.380-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11421.php" xml:lang="en">nokia-6210-vcard-dos(11421)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6952" xml:lang="en">6952</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0104</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:29.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999" xml:lang="en">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10962.php" xml:lang="en">peoplesoft-schedulertransfer-create-files(10962)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7053" xml:lang="en">7053</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:port80_software:servermask:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:port80_software:servermask:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0105</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109215441332682&amp;w=2" xml:lang="en">20040810 Corsaire Security Advisory - Port80 Software ServerMask inconsistencies</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c030224-001.txt" xml:lang="en">http://www.corsaire.com/advisories/c030224-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16947" xml:lang="en">servermask-header-obtain-info(16947)</vuln:reference>
    </vuln:references>
    <vuln:summary>ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:enterprise_firewall:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:enterprise_firewall:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0106</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:34.990-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html" xml:lang="en">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104869513822233&amp;w=2" xml:lang="en">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104868285106289&amp;w=2" xml:lang="en">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754" xml:lang="en">http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7196" xml:lang="en">7196</vuln:reference>
    </vuln:references>
    <vuln:summary>The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:zlib:1.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:zlib:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0107</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-01-02T21:59:00.327-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt" xml:lang="en">CSSA-2003-011.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc" xml:lang="en">NetBSD-SA2003-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619" xml:lang="en">CLSA-2003:619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN78689801/index.html" xml:lang="en">JVN#78689801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000066.html" xml:lang="en">JVNDB-2015-000066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104610337726297&amp;w=2" xml:lang="en">20030223 poc zlib sploit just for fun :)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104610536129508&amp;w=2" xml:lang="en">20030224 Re: buffer overrun in zlib 1.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104620610427210&amp;w=2" xml:lang="en">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104887247624907&amp;w=2" xml:lang="en">GLSA-200303-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://online.securityfocus.com/archive/1/312869" xml:lang="en">20030222 buffer overrun in zlib 1.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405" xml:lang="en">57405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11381.php" xml:lang="en">zlib-gzprintf-bo(11381)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/142121" xml:lang="en">VU#142121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033" xml:lang="en">MDKSA-2003:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-079.html" xml:lang="en">RHSA-2003:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-081.html" xml:lang="en">RHSA-2003:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6913" xml:lang="en">6913</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0108</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:37.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629" xml:lang="en">CLA-2003:629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104637420104189&amp;w=2" xml:lang="en">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104678787109030&amp;w=2" xml:lang="en">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-255" xml:lang="en">DSA-255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/02.27.03.txt" xml:lang="en">http://www.idefense.com/advisory/02.27.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11434.php" xml:lang="en">tcpdump-isakmp-dos(11434)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" xml:lang="en">MDKSA-2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html" xml:lang="en">SuSE-SA:2003:0015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-032.html" xml:lang="en">RHSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-085.html" xml:lang="en">RHSA-2003:085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-214.html" xml:lang="en">RHSA-2003:214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6974" xml:lang="en">6974</vuln:reference>
    </vuln:references>
    <vuln:summary>isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0109</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A109" name="oval:org.mitre.oval:def:109"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104826476427372&amp;w=2" xml:lang="en">20030321 New attack vectors and a vulnerability dissection of MS03-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104861839130254&amp;w=2" xml:lang="en">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104869293619064&amp;w=2" xml:lang="en">20030326 WebDAV exploit: using wide character decoder scheme</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104887148323552&amp;w=2" xml:lang="en">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105768156625699&amp;w=2" xml:lang="en">20030708 WDAV exploit without netcat and with pretty magic number</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104826785731151&amp;w=2" xml:lang="en">20030321 New attack vectors and a vulnerability dissection of MS03-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en" xml:lang="en">http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q815021" xml:lang="en">Q815021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-09.html" xml:lang="en">CA-2003-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029" xml:lang="en">20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11533.php" xml:lang="en">http-webdav-long-request(11533)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/117394" xml:lang="en">VU#117394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf" xml:lang="en">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7116" xml:lang="en">7116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-007" xml:lang="en">MS03-007</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:proxy_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:proxy_server:2.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:isa_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:fp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:proxy_server:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:proxy_server:2.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0110</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:25.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A406" name="oval:org.mitre.oval:def:406"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104994487012027&amp;w=2" xml:lang="en">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/04.09.03.txt" xml:lang="en">http://www.idefense.com/advisory/04.09.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-012" xml:lang="en">MS03-012</vuln:reference>
    </vuln:references>
    <vuln:summary>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_machine:3802"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_machine:3805"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_machine:3809"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:virtual_machine:3802</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_machine:3805</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_machine:3809</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0111</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A136" name="oval:org.mitre.oval:def:136"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11751.php" xml:lang="en">msvm-bytecode-improper-validation(11751)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/447569" xml:lang="en">VU#447569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-011" xml:lang="en">MS03-011</vuln:reference>
    </vuln:references>
    <vuln:summary>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0112</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1264" name="oval:org.mitre.oval:def:1264"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A142" name="oval:org.mitre.oval:def:142"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2022" name="oval:org.mitre.oval:def:2022"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2265" name="oval:org.mitre.oval:def:2265"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A262" name="oval:org.mitre.oval:def:262"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3145" name="oval:org.mitre.oval:def:3145"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A779" name="oval:org.mitre.oval:def:779"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/446338" xml:lang="en">VU#446338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7370" xml:lang="en">7370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-013" xml:lang="en">MS03-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11803" xml:lang="en">win-kernel-lpcrequestwaitreplyport-bo(11803)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0113</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:28.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A926" name="oval:org.mitre.oval:def:926"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105138417416900&amp;w=2" xml:lang="en">20030426 Buffer overflow in Internet Explorer's HTTP parsing code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105718285107246&amp;w=2" xml:lang="en">20030701 URLMON.DLL buffer overflow - technical details</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/169753" xml:lang="en">VU#169753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0114</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:28.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A963" name="oval:org.mitre.oval:def:963"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104429340817718&amp;w=2" xml:lang="en">20030203 internet explorer local file reading</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:summary>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0115</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:29.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11848.php" xml:lang="en">ie-improper-thirdparty-rendering(11848)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0116</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:29.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/244729" xml:lang="en">VU#244729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/301945" xml:lang="en">20021203 Poisonous Style for Dialog window turns the zone off.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6306" xml:lang="en">6306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0117</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:29.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216866132289&amp;w=2" xml:lang="en">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-016" xml:lang="en">MS03-016</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000::developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp1a:developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp1a:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp1a:standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp2:developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp2:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp2:standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000::developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000::enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000::standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp1a:developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp1a:enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp1a:standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp2:developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp2:enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp2:standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0118</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:30.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216839231951&amp;w=2" xml:lang="en">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-016" xml:lang="en">MS03-016</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0119</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:31.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/624713" xml:lang="en">VU#624713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7264" xml:lang="en">7264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IBM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/4699c03b46f2d4f68525678c006d45ae/85256a3400529a8685256cde0008ddde?OpenDocument" xml:lang="en">MSS-OAR-E01-2003:0245.1</vuln:reference>
    </vuln:references>
    <vuln:summary>The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mhc-utils:mhc-utils:0.25_snap2001-06-25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mhc-utils:mhc-utils:0.25_snap2001-06-25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0120</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-256" xml:lang="en">DSA-256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11439.php" xml:lang="en">mhc-adb2mhc-insecure-tmp(11439)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6978" xml:lang="en">6978</vuln:reference>
    </vuln:references>
    <vuln:summary>adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.1</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0121</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:45.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104716030503607&amp;w=2" xml:lang="en">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316311" xml:lang="en">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7044" xml:lang="en">7044</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:r5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:r5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0122</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-12-12T12:05:18.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2017-12-12T10:33:09.027-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html" xml:lang="en">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104757319829443&amp;w=2" xml:lang="en">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/433489" xml:lang="en">VU#433489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0010.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7037" xml:lang="en">7037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101" xml:lang="en">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11526" xml:lang="en">lotus-nrpc-bo(11526)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:r5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:r5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0123</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-11-22T09:04:35.223-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2017-11-21T14:45:06.977-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104757545500368&amp;w=2" xml:lang="en">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/411489" xml:lang="en">VU#411489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0011.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0011.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7038" xml:lang="en">7038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060" xml:lang="en">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11525" xml:lang="en">lotus-web-retriever-bo(11525)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5h1"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5i"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5i2"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5j"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5k"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5h1</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5i</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5i2</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5j</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5k</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0124</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620" xml:lang="en">CLSA-2003:620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104740927915154&amp;w=2" xml:lang="en">20030311 Vulnerability in man &lt; 1.5l</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104802285112752&amp;w=2" xml:lang="en">GLSA-200303-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-133.html" xml:lang="en">RHSA-2003:133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-134.html" xml:lang="en">RHSA-2003:134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7066" xml:lang="en">7066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11512" xml:lang="en">man-myxsprintf-code-execution(11512)</vuln:reference>
    </vuln:references>
    <vuln:summary>man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.63"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.63</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0125</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:19.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.multitech.com/Routers/RF550VPN.TXT" xml:lang="en">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.krusesecurity.dk/advisories/routefind550bof.txt" xml:lang="en">http://www.krusesecurity.dk/advisories/routefind550bof.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7067" xml:lang="en">7067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11514" xml:lang="en">routefinder-vpn-options-bo(11514)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.63"/>
        <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.64_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.63</vuln:product>
      <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.64_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0126</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:33.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.krusesecurity.dk/advisories/routefind550bof.txt" xml:lang="en">http://www.krusesecurity.dk/advisories/routefind550bof.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0127</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:19.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254" name="oval:org.mitre.oval:def:254"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt" xml:lang="en">CSSA-2003-020.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html" xml:lang="en">20030317 Fwd: Ptrace hole / Linux 2.2.25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105301461726555&amp;w=2" xml:lang="en">ESA-20030515-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-088.html" xml:lang="en">RHSA-2003:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-098.html" xml:lang="en">RHSA-2003:098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200303-17.xml" xml:lang="en">GLSA-200303-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-270" xml:lang="en">DSA-270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-276" xml:lang="en">DSA-276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/628849" xml:lang="en">VU#628849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038" xml:lang="en">MDKSA-2003:038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039" xml:lang="en">MDKSA-2003:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-103.html" xml:lang="en">RHSA-2003:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-145.html" xml:lang="en">RHSA-2003:145</vuln:reference>
    </vuln:references>
    <vuln:summary>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.0.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.5</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.6</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.7</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.8</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.1.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0128</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A107" name="oval:org.mitre.oval:def:107"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" xml:lang="en">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" xml:lang="en">CLA-2003:648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104826470527308&amp;w=2" xml:lang="en">20030321 GLSA:  evolution (200303-18)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" xml:lang="en">GLSA-200303-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" xml:lang="en">MDKSA-2003:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-108.html" xml:lang="en">RHSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7117" xml:lang="en">7117</vuln:reference>
    </vuln:references>
    <vuln:summary>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.0.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.5</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.6</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.7</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.8</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.1.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0129</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A108" name="oval:org.mitre.oval:def:108"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" xml:lang="en">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" xml:lang="en">CLA-2003:648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104826470527308&amp;w=2" xml:lang="en">20030321 GLSA:  evolution (200303-18)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" xml:lang="en">GLSA-200303-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" xml:lang="en">MDKSA-2003:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-108.html" xml:lang="en">RHSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7118" xml:lang="en">7118</vuln:reference>
    </vuln:references>
    <vuln:summary>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.0.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.5</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.6</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.7</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.8</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.1.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0130</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A111" name="oval:org.mitre.oval:def:111"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" xml:lang="en">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" xml:lang="en">CLA-2003:648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104826470527308&amp;w=2" xml:lang="en">20030321 GLSA:  evolution (200303-18)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" xml:lang="en">GLSA-200303-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" xml:lang="en">MDKSA-2003:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-108.html" xml:lang="en">RHSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7119" xml:lang="en">7119</vuln:reference>
    </vuln:references>
    <vuln:summary>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0131</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:23.713-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A461" name="oval:org.mitre.oval:def:461"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc" xml:lang="en">NetBSD-SA2003-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" xml:lang="en">CSSA-2003-014.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" xml:lang="en">20030501-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" xml:lang="en">CLA-2003:625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://eprint.iacr.org/2003/052/" xml:lang="en">http://eprint.iacr.org/2003/052/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104811162730834&amp;w=2" xml:lang="en">20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104852637112330&amp;w=2" xml:lang="en">20030324 GLSA:  openssl (200303-20)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104878215721135&amp;w=2" xml:lang="en">2003-0013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-288" xml:lang="en">DSA-288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml" xml:lang="en">GLSA-200303-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/888801" xml:lang="en">VU#888801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" xml:lang="en">http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035" xml:lang="en">MDKSA-2003:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html" xml:lang="en">OpenPKG-SA-2003.026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20030319.txt" xml:lang="en">http://www.openssl.org/news/secadv_20030319.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-101.html" xml:lang="en">RHSA-2003:101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-102.html" xml:lang="en">RHSA-2003:102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316577/30/25310/threaded" xml:lang="en">IMNX-2003-7+-001-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7148" xml:lang="en">7148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11586" xml:lang="en">ssl-premaster-information-leak(11586)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="https://lists.opensuse.org/opensuse-security-announce/2003-04/msg00005.html" xml:lang="en">SuSE-SA:2003:024</vuln:reference>
    </vuln:references>
    <vuln:summary>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0132</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A156" name="oval:org.mitre.oval:def:156"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104931360606484&amp;w=2" xml:lang="en">20030402 [ANNOUNCE] Apache 2.0.45 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104982175321731&amp;w=2" xml:lang="en">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104994239010517&amp;w=2" xml:lang="en">20030409 GLSA:  apache (200304-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104994309010974&amp;w=2" xml:lang="en">20030408 Exploit Code Released for Apache 2.x Memory Leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105001663120995&amp;w=2" xml:lang="en">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105013378320711&amp;w=2" xml:lang="en">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147" xml:lang="en">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/04.08.03.txt" xml:lang="en">http://www.idefense.com/advisory/04.08.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/206537" xml:lang="en">VU#206537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-139.html" xml:lang="en">RHSA-2003:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1233" xml:lang="en">ADV-2009-1233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gtkhtml:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gtkhtml:1.1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gtkhtml:1.1.9</vuln:product>
      <vuln:product>cpe:/a:gnome:gtkhtml:1.1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0133</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A138" name="oval:org.mitre.oval:def:138"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" xml:lang="en">CLA-2003:737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046" xml:lang="en">MDKSA-2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-126.html" xml:lang="en">RHSA-2003:126</vuln:reference>
    </vuln:references>
    <vuln:summary>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0134</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:29:58.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35" xml:lang="en">http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104931360606484&amp;w=2" xml:lang="en">20030402 [ANNOUNCE] Apache 2.0.45 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105418115512559&amp;w=2" xml:lang="en">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0135</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:05.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A634" name="oval:org.mitre.oval:def:634"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-084.html" xml:lang="en">RHSA-2003:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7253" xml:lang="en">7253</vuln:reference>
    </vuln:references>
    <vuln:summary>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.8.9"/>
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.8.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.7.4</vuln:product>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.8.9</vuln:product>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.8.10.1</vuln:product>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.8.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0136</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A423" name="oval:org.mitre.oval:def:423"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-285" xml:lang="en">DSA-285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-142.html" xml:lang="en">RHSA-2003:142</vuln:reference>
    </vuln:references>
    <vuln:summary>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nokia:sgsn_dx200"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:sgsn_dx200</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0137</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a031303-2.txt" xml:lang="en">A031303-2</vuln:reference>
    </vuln:references>
    <vuln:summary>SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0138</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:25.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A248" name="oval:org.mitre.oval:def:248"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104791775804776&amp;w=2" xml:lang="en">20030317 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 protocol</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-269" xml:lang="en">DSA-269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-273" xml:lang="en">DSA-273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/623217" xml:lang="en">VU#623217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7113" xml:lang="en">7113</vuln:reference>
    </vuln:references>
    <vuln:summary>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0139</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:25.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A250" name="oval:org.mitre.oval:def:250"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104791775804776&amp;w=2" xml:lang="en">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-273" xml:lang="en">DSA-273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/442569" xml:lang="en">VU#442569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317130/30/25250/threaded" xml:lang="en">20030330 GLSA: openafs (200303-26)</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.16</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.17</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.22</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.24</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.25</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.27</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.4.0</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0140</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2" name="oval:org.mitre.oval:def:2"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A434" name="oval:org.mitre.oval:def:434"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626" xml:lang="en">CLA-2003:626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630" xml:lang="en">CLA-2003:630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104817995421439&amp;w=2" xml:lang="en">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104818814931378&amp;w=2" xml:lang="en">20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104852190605988&amp;w=2" xml:lang="en">20030322 GLSA:  mutt (200303-19)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105171507629573&amp;w=2" xml:lang="en">20030430 GLSA:  balsa (200304-10)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-268" xml:lang="en">DSA-268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml" xml:lang="en">GLSA-200303-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041" xml:lang="en">MDKSA-2003:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_020_mutt.html" xml:lang="en">SuSE-SA:2003:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-109.html" xml:lang="en">RHSA-2003:109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315679" xml:lang="en">20030319 mutt-1.4.1 fixes a buffer overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7120" xml:lang="en">7120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11583" xml:lang="en">mutt-folder-name-bo(11583)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.10.505:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.818"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.830"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.841"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.853"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:9.0.0.288"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:9.0.0.297"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.10.505:gold</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.818</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.830</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.841</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.853</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:9.0.0.288</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:9.0.0.297</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0141</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:03.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html" xml:lang="en">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104887465427579&amp;w=2" xml:lang="en">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/705761" xml:lang="en">VU#705761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7177" xml:lang="en">7177</vuln:reference>
    </vuln:references>
    <vuln:summary>The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0142</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:35.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/689835" xml:lang="en">VU#689835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/328224" xml:lang="en">20030708 Adobe Acrobat and PDF security: no improvements for 2 years</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.1</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.2</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.3</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0143</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104739841223916&amp;w=2" xml:lang="en">20030310 QPopper 4.0.x buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104748775900481&amp;w=2" xml:lang="en">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104768137314397&amp;w=2" xml:lang="en">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792541215354&amp;w=2" xml:lang="en">GLSA-200303-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-259" xml:lang="en">DSA-259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html" xml:lang="en">SuSE-SA:2003:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7058" xml:lang="en">7058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11516" xml:lang="en">qpopper-popmsg-macroname-bo(11516)</vuln:reference>
    </vuln:references>
    <vuln:summary>The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lprold:lprold:3.0.48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:bsd:lpr:0.48"/>
        <cpe-lang:fact-ref name="cpe:/o:bsd:lpr:2000-05-07"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lprold:lprold:3.0.48</vuln:product>
      <vuln:product>cpe:/o:bsd:lpr:0.48</vuln:product>
      <vuln:product>cpe:/o:bsd:lpr:2000-05-07</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0144</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch" xml:lang="en">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P" xml:lang="en">20030406-02-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104690434504429&amp;w=2" xml:lang="en">20030305 potential buffer overflow in lprm (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104714441925019&amp;w=2" xml:lang="en">20030308 OpenBSD lprm(1) exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-267" xml:lang="en">DSA-267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-275" xml:lang="en">DSA-275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059" xml:lang="en">MDKSA-2003:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_014_lprold.html" xml:lang="en">SuSE-SA:2003:0014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7025" xml:lang="en">7025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11473" xml:lang="en">lprm-bo(11473)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0145</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-261" xml:lang="en">DSA-261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" xml:lang="en">MDKSA-2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-032.html" xml:lang="en">RHSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-151.html" xml:lang="en">RHSA-2003:151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-214.html" xml:lang="en">RHSA-2003:214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tcpdump.org/tcpdump-changes.txt" xml:lang="en">http://www.tcpdump.org/tcpdump-changes.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11857" xml:lang="en">tcpdump-radius-attribute-dos(11857)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netpbm:netpbm:9.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netpbm:netpbm:9.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0146</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:27.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656" xml:lang="en">CLSA-2003:656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104644687816522&amp;w=2" xml:lang="en">20030228 NetPBM, multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-263" xml:lang="en">DSA-263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/630433" xml:lang="en">VU#630433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-060.html" xml:lang="en">RHSA-2003:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6979" xml:lang="en">6979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11463" xml:lang="en">netpbm-multiple-bo(11463)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openpkg:openpkg</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:1.1</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:1.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.7</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.8</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.9</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.10</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.11</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.12</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.13</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.14</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.15</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.16</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.17</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.18</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.19</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.20</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.21</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.22</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.0</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.01</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.02</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.03</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0147</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:26.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A466" name="oval:org.mitre.oval:def:466"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" xml:lang="en">CSSA-2003-014.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" xml:lang="en">20030501-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html" xml:lang="en">20030313 OpenSSL Private Key Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf" xml:lang="en">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" xml:lang="en">CLA-2003:625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104766550528628&amp;w=2" xml:lang="en">20030313 Vulnerability in OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792570615648&amp;w=2" xml:lang="en">20030317 [ADVISORY] Timing Attack on OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104819602408063&amp;w=2" xml:lang="en">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104829040921835&amp;w=2" xml:lang="en">GLSA-200303-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104861762028637&amp;w=2" xml:lang="en">GLSA-200303-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-288" xml:lang="en">DSA-288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml" xml:lang="en">GLSA-200303-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/997481" xml:lang="en">VU#997481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035" xml:lang="en">MDKSA-2003:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html" xml:lang="en">OpenPKG-SA-2003.019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20030317.txt" xml:lang="en">http://www.openssl.org/news/secadv_20030317.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-101.html" xml:lang="en">RHSA-2003:101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-102.html" xml:lang="en">RHSA-2003:102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316577/30/25310/threaded" xml:lang="en">IMNX-2003-7+-001-01</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0148</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:05.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a073103-1.txt" xml:lang="en">A073103-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" xml:lang="en">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</vuln:reference>
    </vuln:references>
    <vuln:summary>The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0149</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:05.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a073103-1.txt" xml:lang="en">A073103-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" xml:lang="en">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.52"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.55"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:mysql:3.23.52</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.55</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0150</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-07T12:41:11.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A442" name="oval:org.mitre.oval:def:442"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" xml:lang="en">CLA-2003:743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104715840202315&amp;w=2" xml:lang="en">20030308 MySQL_user_can_be_changed_to_root?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104739810523433&amp;w=2" xml:lang="en">20030310 Re: MySQL user can be changed to root</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104800948128630&amp;w=2" xml:lang="en">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104802285012750&amp;w=2" xml:lang="en">20030318 GLSA:  mysql (200303-14)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-094.html" xml:lang="en">RHSA-2003:094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-303" xml:lang="en">DSA-303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/203897" xml:lang="en">VU#203897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html" xml:lang="en">ESA-20030324-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057" xml:lang="en">MDKSA-2003:057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-093.html" xml:lang="en">RHSA-2003:093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7052" xml:lang="en">7052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11510" xml:lang="en">mysql-datadir-root-privileges(11510)</vuln:reference>
    </vuln:references>
    <vuln:summary>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0151</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:09.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792477914620&amp;w=2" xml:lang="en">20030317 SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104792544515384&amp;w=2" xml:lang="en">20030317 S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/en/avisos/s21sec-011-en.txt" xml:lang="en">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7122" xml:lang="en">7122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7124" xml:lang="en">7124</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0152</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:37.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7162" xml:lang="en">7162</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0153</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=187230" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=102980129101054&amp;w=2" xml:lang="en">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5517" xml:lang="en">5517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/9921" xml:lang="en">bonsai-path-disclosure(9921)</vuln:reference>
    </vuln:references>
    <vuln:summary>bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0154</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:12.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view" xml:lang="en">http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view" xml:lang="en">http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=146244" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=163573" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=102980129101054&amp;w=2" xml:lang="en">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/9920.php" xml:lang="en">bonsai-error-message-xss(9920)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5516" xml:lang="en">5516</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0155</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:37.863-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7163" xml:lang="en">7163</vuln:reference>
    </vuln:references>
    <vuln:summary>bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.3</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.8</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.9</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.9.1</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0156</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:13.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104739747222492&amp;w=2" xml:lang="en">20030311 Cross-Referencing Linux vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-264" xml:lang="en">DSA-264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7062" xml:lang="en">7062</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0157">
    <vuln:cve-id>CVE-2003-0157</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:08.460-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0158">
    <vuln:cve-id>CVE-2003-0158</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:08.710-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.0</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0159</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A55" name="oval:org.mitre.oval:def:55"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104741640924709&amp;w=2" xml:lang="en">20030309 GLSA:  ethereal (200303-10)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00008.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00008.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051" xml:lang="en">MDKSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" xml:lang="en">SuSE-SA:2003:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7050" xml:lang="en">7050</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0160</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A614" name="oval:org.mitre.oval:def:614"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988" xml:lang="en">http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-112.html" xml:lang="en">RHSA-2003:112</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta16"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d_pk9_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_700:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_800:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:sis"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta12</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta16</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.8</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d_pk9_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.0.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_700:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_800:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:sis</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0161</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt" xml:lang="en">CSSA-2003-016.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc" xml:lang="en">FreeBSD-SA-03:07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt" xml:lang="en">SCOSA-2004.11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P" xml:lang="en">20030401-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614" xml:lang="en">CLA-2003:614</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html" xml:lang="en">20030329 Sendmail: -1 gone wild</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104896621106790&amp;w=2" xml:lang="en">20030329 sendmail 8.12.9 available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104897487512238&amp;w=2" xml:lang="en">20030329 Sendmail: -1 gone wild</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104914999806315&amp;w=2" xml:lang="en">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1" xml:lang="en">52620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1" xml:lang="en">52700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001088.1-1" xml:lang="en">1001088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-12.html" xml:lang="en">CA-2003-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-278" xml:lang="en">DSA-278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-290" xml:lang="en">DSA-290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml" xml:lang="en">GLSA-200303-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/897604" xml:lang="en">VU#897604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-120.html" xml:lang="en">RHSA-2003:120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-121.html" xml:lang="en">RHSA-2003:121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316961/30/25250/threaded" xml:lang="en">20030331 GLSA: sendmail (200303-27)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317135/30/25220/threaded" xml:lang="en">20030401 Immunix Secured OS 7+ openssl update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321997" xml:lang="en">20030520 [Fwd: 127 Research and Development: 127 Day!]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7230" xml:lang="en">7230</vuln:reference>
    </vuln:references>
    <vuln:summary>The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-10-13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-10-13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0162</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104636153214262&amp;w=2" xml:lang="en">20030227 Ecardis Password Reseting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104673407728323&amp;w=2" xml:lang="en">20030303 Re: Ecardis Password Reseting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-271" xml:lang="en">DSA-271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6971" xml:lang="en">6971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11431" xml:lang="en">ecartis-password-reset(11431)</vuln:reference>
    </vuln:references>
    <vuln:summary>Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gaim-encryption:gaim-encryption:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:gaim-encryption:gaim-encryption:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:gaim-encryption:gaim-encryption:1.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gaim-encryption:gaim-encryption:1.13</vuln:product>
      <vuln:product>cpe:/a:gaim-encryption:gaim-encryption:1.14</vuln:product>
      <vuln:product>cpe:/a:gaim-encryption:gaim-encryption:1.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0163</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:17.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105013281120352&amp;w=2" xml:lang="en">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0013.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0013.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7182" xml:lang="en">7182</vuln:reference>
    </vuln:references>
    <vuln:summary>decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:2.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:eog:1.0.0</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.1</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.2</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.3</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.4</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:2.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0165</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A52" name="oval:org.mitre.oval:def:52"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html" xml:lang="en">20030328 Vulnerability in GNOME's Eye of Gnome</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104887189724146&amp;w=2" xml:lang="en">20030328 CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/363001" xml:lang="en">VU#363001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048" xml:lang="en">MDKSA-2003:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-128.html" xml:lang="en">RHSA-2003:128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7121" xml:lang="en">7121</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0166</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" xml:lang="en">CLSA-2003:691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104869828526885&amp;w=2" xml:lang="en">20030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104878100719467&amp;w=2" xml:lang="en">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104931415307111&amp;w=2" xml:lang="en">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7197" xml:lang="en">7197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7198" xml:lang="en">7198</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.28"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12.1</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.16</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.17</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.22</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.24</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.25</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.27</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.28</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0167</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:39.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-274" xml:lang="en">DSA-274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-300" xml:lang="en">DSA-300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7229" xml:lang="en">7229</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0168</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:33.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html" xml:lang="en">20030331 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00027.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00027.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/03.31.03.txt" xml:lang="en">http://www.idefense.com/advisory/03.31.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/112553" xml:lang="en">VU#112553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317141/30/25220/threaded" xml:lang="en">20030401 Fwd: QuickTime 6.1 for Windows is available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317148/30/25220/threaded" xml:lang="en">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7247" xml:lang="en">7247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11671" xml:lang="en">quicktime-url-bo(11671)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:instant_toptools:5.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:instant_toptools:5.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0169</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:21.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html" xml:lang="en">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104914959705949&amp;w=2" xml:lang="en">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7246" xml:lang="en">7246</vuln:reference>
    </vuln:references>
    <vuln:summary>hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0170</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7346" xml:lang="en">7346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IBM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0469.1" xml:lang="en">MSS-OAR-E01-2003.0469.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY42424" xml:lang="en">IY42424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11823" xml:lang="en">aix-ftpd-gain-access(11823)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0171</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:10.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a041003-1.txt" xml:lang="en">A041003-1</vuln:reference>
    </vuln:references>
    <vuln:summary>DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0172</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104878149020152&amp;w=2" xml:lang="en">20030327 @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104931415307111&amp;w=2" xml:lang="en">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316583" xml:lang="en">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/385238" xml:lang="en">20041222 PHP v4.3.x exploit for Windows.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7210" xml:lang="en">7210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11637" xml:lang="en">php-openlog-stack-bo(11637)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.0</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.1</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.2</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.3</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.4</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0173</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:10.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P" xml:lang="en">20030404-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-283" xml:lang="en">DSA-283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/111673" xml:lang="en">VU#111673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047" xml:lang="en">MDKSA-2003:047</vuln:reference>
    </vuln:references>
    <vuln:summary>xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0174</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P" xml:lang="en">20030407-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-084.shtml" xml:lang="en">N-084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7442" xml:lang="en">7442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11860" xml:lang="en">irix-ldap-authentication-bypass(11860)</vuln:reference>
    </vuln:references>
    <vuln:summary>The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0175</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P" xml:lang="en">20030603-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/142228" xml:lang="en">VU#142228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7868" xml:lang="en">7868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008770" xml:lang="en">1008770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12241" xml:lang="en">irix-piocswatch-ioctl-dos(12241)</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0176</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" xml:lang="en">20030701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0177</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" xml:lang="en">20030701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0178</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html" xml:lang="en">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html" xml:lang="en">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550063431461&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550063431463&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550335103136&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104558777331345&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104558777531350&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/206361" xml:lang="en">VU#206361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/542873" xml:lang="en">VU#542873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/772817" xml:lang="en">VU#772817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6870" xml:lang="en">6870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6871" xml:lang="en">6871</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11336" xml:lang="en">lotus-domino-inotes-bo(11336)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11337" xml:lang="en">lotus-domino-hostname-bo(11337)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0179</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550124032513&amp;w=2" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104550335103136&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104558778131373&amp;w=2" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/571297" xml:lang="en">VU#571297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6872" xml:lang="en">6872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21104543" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11339" xml:lang="en">lotus-notes-activex-bo(11339)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0180</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" xml:lang="en">20030218 More Lotus Domino Advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/355169" xml:lang="en">VU#355169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-60dos.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-60dos.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6951" xml:lang="en">6951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11360" xml:lang="en">lotus-incomplete-post-dos(11360)</vuln:reference>
    </vuln:references>
    <vuln:summary>Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0181</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" xml:lang="en">20030218 More Lotus Domino Advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-60dos.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-60dos.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6951" xml:lang="en">6951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11361" xml:lang="en">lotus-invalid-field-dos(11361)</vuln:reference>
    </vuln:references>
    <vuln:summary>Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0187</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A260" name="oval:org.mitre.oval:def:260"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105986028426824&amp;w=2" xml:lang="en">20030802 [SECURITY] Netfilter Security Advisory: Conntrack list_del() DoS</vuln:reference>
    </vuln:references>
    <vuln:summary>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.3"/>
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.4"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-1::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-3::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-7::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-9::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lv:lv:4.49.1</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.2</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.3</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.4</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-1::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-3::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-7::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-9::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0188</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A430" name="oval:org.mitre.oval:def:430"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-304" xml:lang="en">DSA-304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-167.html" xml:lang="en">RHSA-2003:167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-169.html" xml:lang="en">RHSA-2003:169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-35.txt" xml:lang="en">TLSA-2003-35</vuln:reference>
    </vuln:references>
    <vuln:summary>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0189</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" xml:lang="en">CLA-2003:661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105418115512559&amp;w=2" xml:lang="en">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/httpd/Announcement2.html" xml:lang="en">http://www.apache.org/dist/httpd/Announcement2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/479268" xml:lang="en">VU#479268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-186.html" xml:lang="en">RHSA-2003:186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7725" xml:lang="en">7725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12091" xml:lang="en">apache-aprpasswordvalidate-dos(12091)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.4p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6.1p1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.4p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.6.1p1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0190</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A445" name="oval:org.mitre.oval:def:445"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lab.mediaservice.net/advisory/2003-01-openssh.txt" xml:lang="en">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html" xml:lang="en">20030430 OpenSSH/PAM timing attack allows remote users identification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105172058404810&amp;w=2" xml:lang="en">20030430 OpenSSH/PAM timing attack allows remote users identification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106018677302607&amp;w=2" xml:lang="en">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-222.html" xml:lang="en">RHSA-2003:222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-224.html" xml:lang="en">RHSA-2003:224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7467" xml:lang="en">7467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-31.txt" xml:lang="en">TLSA-2003-31</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0192</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:19.850-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A169" name="oval:org.mitre.oval:def:169"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" xml:lang="en">SCOSA-2004.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105776593602600&amp;w=2" xml:lang="en">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" xml:lang="en">MDKSA-2003:075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-240.html" xml:lang="en">RHSA-2003:240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-243.html" xml:lang="en">RHSA-2003:243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-244.html" xml:lang="en">RHSA-2003:244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:catdoc:catdoc:0.91"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:catdoc:catdoc:0.91</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0193</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-575" xml:lang="en">DSA-575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11560" xml:lang="en">11560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16335" xml:lang="en">catdoc-xlsview-symlink(16335)</vuln:reference>
    </vuln:references>
    <vuln:summary>msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.4-39::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.2-9::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.2-9::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.2-12::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.3-3::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.7.2-1::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:tcpdump:3.4-39::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.2-9::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.2-9::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.2-12::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.3-3::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.7.2-1::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0194</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:43.270-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-151.html" xml:lang="en">RHSA-2003:151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-174.html" xml:lang="en">RHSA-2003:174</vuln:reference>
    </vuln:references>
    <vuln:summary>tcpdump does not properly drop privileges to the pcap user when starting up.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:8.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0195</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6" name="oval:org.mitre.oval:def:6"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000678" xml:lang="en">CLSA-2003:678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105427288724449&amp;w=2" xml:lang="en">20030529 [slackware-security]  CUPS DoS vulnerability fixed (SSA:2003-149-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-317" xml:lang="en">DSA-317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:062" xml:lang="en">MDKSA-2003:062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_028.html" xml:lang="en">SuSE-SA:2003:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-171.html" xml:lang="en">RHSA-2003:171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7637" xml:lang="en">7637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-33.txt" xml:lang="en">TLSA-2003-33</vuln:reference>
    </vuln:references>
    <vuln:summary>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d_pk9_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.05</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.06</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.07</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.02</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.8</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d_pk9_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0196</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A564" name="oval:org.mitre.oval:def:564"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104973186901597&amp;w=2" xml:lang="en">20030407 [OpenPKG-SA-2003.028] OpenPKG Security Advisory (samba)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104974612519064&amp;w=2" xml:lang="en">20030407 Immunix Secured OS 7+ samba update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-280" xml:lang="en">DSA-280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" xml:lang="en">MDKSA-2003:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-137.html" xml:lang="en">RHSA-2003:137</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:borland_software:interbase:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:borland_software:interbase:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:borland_software:interbase:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:firebirdsql:firebird:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:borland_software:interbase:6.0</vuln:product>
      <vuln:product>cpe:/a:borland_software:interbase:6.4</vuln:product>
      <vuln:product>cpe:/a:borland_software:interbase:6.5</vuln:product>
      <vuln:product>cpe:/a:firebirdsql:firebird:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0197</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:32.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html" xml:lang="en">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104940730819887&amp;w=2" xml:lang="en">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0198</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:13.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0199">
    <vuln:cve-id>CVE-2003-0199</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.777-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.777-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0200">
    <vuln:cve-id>CVE-2003-0200</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.807-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.807-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d_pk9_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.05</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.06</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.07</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.02</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.8</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d_pk9_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0201</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2163" name="oval:org.mitre.oval:def:2163"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A567" name="oval:org.mitre.oval:def:567"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P" xml:lang="en">20030403-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624" xml:lang="en">CLA-2003:624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104972664226781&amp;w=2" xml:lang="en">20030407 [DDI-1013] Buffer Overflow in Samba allows remote root compromise</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104974612519064&amp;w=2" xml:lang="en">20030407 Immunix Secured OS 7+ samba update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104981682014565&amp;w=2" xml:lang="en">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104994564212488&amp;w=2" xml:lang="en">20030409 GLSA:  samba (200304-02)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-280" xml:lang="en">DSA-280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt" xml:lang="en">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/267873" xml:lang="en">VU#267873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" xml:lang="en">MDKSA-2003:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_025_samba.html" xml:lang="en">SuSE-SA:2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-137.html" xml:lang="en">RHSA-2003:137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7294" xml:lang="en">7294</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brian_renaud:metrics:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brian_renaud:metrics:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0202</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-279" xml:lang="en">DSA-279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7293" xml:lang="en">7293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11734" xml:lang="en">metrics-tmpfile-symlink(11734)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:moxftp:moxftp:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xftp:xftp:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:moxftp:moxftp:2.2</vuln:product>
      <vuln:product>cpe:/a:xftp:xftp:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0203</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:28.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104610380126860&amp;w=2" xml:lang="en">20030223 moxftp arbitrary code execution poc/advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-281" xml:lang="en">DSA-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html" xml:lang="en">20030223 moxftp arbitrary code execution poc/advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6921" xml:lang="en">6921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006156" xml:lang="en">1006156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11399" xml:lang="en">moxftp-welcome-banner-bo(11399)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:2.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0204</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:36.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.kde.org/show_bug.cgi?id=53343" xml:lang="en">http://bugs.kde.org/show_bug.cgi?id=53343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.kde.org/show_bug.cgi?id=56808" xml:lang="en">http://bugs.kde.org/show_bug.cgi?id=56808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668" xml:lang="en">CLA-2003:668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" xml:lang="en">CLA-2003:747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105001557020141&amp;w=2" xml:lang="en">20030410 GLSA:  kde-3.x (200304-04)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105012994719099&amp;w=2" xml:lang="en">20030411 GLSA:  kde-2.x (200304-05)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105017403010459&amp;w=2" xml:lang="en">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105034222521369&amp;w=2" xml:lang="en">20030414 GLSA:  kde-2.x (200304-05.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-284" xml:lang="en">DSA-284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-293" xml:lang="en">DSA-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-296" xml:lang="en">DSA-296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20030409-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20030409-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049" xml:lang="en">MDKSA-2003:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-002.html" xml:lang="en">RHSA-2003:002</vuln:reference>
    </vuln:references>
    <vuln:summary>KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0205</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:37.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105111327000755&amp;w=2" xml:lang="en">20030423 Security problems in gkrellm-newsticker</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-294" xml:lang="en">DSA-294</vuln:reference>
    </vuln:references>
    <vuln:summary>gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0206</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:39.033-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105111327000755&amp;w=2" xml:lang="en">20030423 Security problems in gkrellm-newsticker</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-294" xml:lang="en">DSA-294</vuln:reference>
    </vuln:references>
    <vuln:summary>gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gs-common:gs-common:0.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gs-common:gs-common:0.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0207</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:15.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-286" xml:lang="en">DSA-286</vuln:reference>
    </vuln:references>
    <vuln:summary>ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macromedia:flash</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0208</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:40.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html" xml:lang="en">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105033712615013&amp;w=2" xml:lang="en">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm" xml:lang="en">http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/5XP0B0U9PE.html" xml:lang="en">http://www.securiteam.com/securitynews/5XP0B0U9PE.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smoothwall:smoothwall:2.0_beta_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smoothwall:smoothwall:2.0_beta_4</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.1</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.2</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.3</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.4</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.5</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.6</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.7</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.9</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0209</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:41.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105043563016235&amp;w=2" xml:lang="en">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105103586927007&amp;w=2" xml:lang="en">20030422 GLSA:  snort (200304-05)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105111217731583&amp;w=2" xml:lang="en">20030423 Snort &lt;=1.9.1 exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105154530427824&amp;w=2" xml:lang="en">20030428 GLSA:  snort (200304-06)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105172790914107&amp;w=2" xml:lang="en">ESA-20030430-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-13.html" xml:lang="en">CA-2003-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-297" xml:lang="en">DSA-297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/139129" xml:lang="en">VU#139129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052" xml:lang="en">MDKSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7178" xml:lang="en">7178</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.3</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.4</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.5</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6.2</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6.3</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6.4</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.0</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.0.3</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0210</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:42.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105120066126196&amp;w=2" xml:lang="en">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105118056332344&amp;w=2" xml:lang="en">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml" xml:lang="en">20030423 Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/697049" xml:lang="en">VU#697049</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.0</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.1</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.2</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.3</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.4</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.5</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.6</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.7</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.8</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.9</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0211</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:06.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A657" name="oval:org.mitre.oval:def:657"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782" xml:lang="en">CLA-2003:782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105068673220605&amp;w=2" xml:lang="en">20030418 Xinetd 2.3.10 Memory Leaks</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056" xml:lang="en">MDKSA-2003:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-160.html" xml:lang="en">RHSA-2003:160</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rinetd:rinetd:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:rinetd:rinetd:0.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rinetd:rinetd:0.52</vuln:product>
      <vuln:product>cpe:/a:rinetd:rinetd:0.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0212</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:45.660-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105059298502830&amp;w=2" xml:lang="en">20030417 Vulnerability in rinetd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-289" xml:lang="en">DSA-289</vuln:reference>
    </vuln:references>
    <vuln:summary>handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.3_2002-10-09"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b1"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:poptop:pptp_server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.2</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.3</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.3_2002-10-09</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b1</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0213</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:46.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105068728421160&amp;w=2" xml:lang="en">20030418 Exploit for PoPToP PPTP server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105154539727967&amp;w=2" xml:lang="en">20030428 GLSA:  pptpd (200304-08)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=138437" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=138437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-295" xml:lang="en">DSA-295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/673993" xml:lang="en">VU#673993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_029.html" xml:lang="en">SuSE-SA:2003:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317995" xml:lang="en">20030409 PoPToP PPTP server remotely exploitable buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319428" xml:lang="en">20030422 Re: Exploit for PoPToP PPTP server - Linux version</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7316" xml:lang="en">7316</vuln:reference>
    </vuln:references>
    <vuln:summary>ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:mime-support:3.9</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.10</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.11</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.12</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.13</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.14</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.15</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.16</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.17</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.18</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.19</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.20</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0214</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:46.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-292" xml:lang="en">DSA-292</vuln:reference>
    </vuln:references>
    <vuln:summary>run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:battleaxe_software:bttlxeforum:2.0_beta_3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:battleaxe_software:bttlxeforum:2.0_beta_3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0215</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:48.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105120052725940&amp;w=2" xml:lang="en">20030424 SQL injection in BttlxeForum</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006632" xml:lang="en">1006632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812" xml:lang="en">http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:7.5%281%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:catos:7.5%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0216</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:16.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml." xml:lang="en">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/443257" xml:lang="en">VU#443257</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0217</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:50.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105283833617480&amp;w=2" xml:lang="en">20030513 XSS In Neoteris IVE Allows Session Hijacking</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.1.1</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.5.2</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.6.0</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0218</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:51.457-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html" xml:lang="en">20030420 Monkey HTTPd Remote Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105094204204166&amp;w=2" xml:lang="en">20030420 Monkey HTTPd Remote Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105154473526898&amp;w=2" xml:lang="en">20030428 GLSA:  monkeyd (200304-07.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://monkeyd.sourceforge.net/Changelog.txt" xml:lang="en">http://monkeyd.sourceforge.net/Changelog.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7202" xml:lang="en">7202</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.2</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.3</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0219</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:52.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105155734411836&amp;w=2" xml:lang="en">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/641012" xml:lang="en">VU#641012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7179" xml:lang="en">7179</vuln:reference>
    </vuln:references>
    <vuln:summary>Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.2</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.3</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0220</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:30:53.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105155734411836&amp;w=2" xml:lang="en">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/454716" xml:lang="en">VU#454716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7180" xml:lang="en">7180</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1b:pk1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:tru64:5.1b:pk1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0221</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-086.shtml" xml:lang="en">SSRT3471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7452" xml:lang="en">7452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11892" xml:lang="en">tru64-dupatch-setld-symlink(11892)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:7.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:7.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.0.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.0x"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1x"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:7.3.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:7.3.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.5.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.1.6</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.0.6.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.0x</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.6</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1x</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0222</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105162831008176&amp;w=2" xml:lang="en">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105163376015735&amp;w=2" xml:lang="en">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-085.shtml" xml:lang="en">N-085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7453" xml:lang="en">7453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11885" xml:lang="en">oracle-database-link-bo(11885)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0223">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_services:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_services:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0223</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A66" name="oval:org.mitre.oval:def:66"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018" xml:lang="en">MS03-018</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_services:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_services:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0224</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A483" name="oval:org.mitre.oval:def:483"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105431767100944&amp;w=2" xml:lang="en">20030530 NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018" xml:lang="en">MS03-018</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_services:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_services:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0225</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A373" name="oval:org.mitre.oval:def:373"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105110606122772&amp;w=2" xml:lang="en">20030418 Microsoft Active Server Pages DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aqtronix.com/Advisories/AQ-2003-01.txt" xml:lang="en">http://www.aqtronix.com/Advisories/AQ-2003-01.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018" xml:lang="en">MS03-018</vuln:reference>
    </vuln:references>
    <vuln:summary>The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0226">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_services:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_services:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0226</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A933" name="oval:org.mitre.oval:def:933"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0308.html" xml:lang="en">20030528 Internet Information Services 5.0 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105427362724860&amp;w=2" xml:lang="en">20030529 IIS WEBDAV Denial of Service attacks</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105421243732552&amp;w=2" xml:lang="en">20030528 Internet Information Services 5.0 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.spidynamics.com/iis_alert.html" xml:lang="en">http://www.spidynamics.com/iis_alert.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018" xml:lang="en">MS03-018</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0227">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0227</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:32.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A936" name="oval:org.mitre.oval:def:936"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A966" name="oval:org.mitre.oval:def:966"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105427615626177&amp;w=2" xml:lang="en">20030528 RE: Alert: MS03-019, Microsoft... wrong, again.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105421127531558&amp;w=2" xml:lang="en">20030528 Re: Alert: MS03-019, Microsoft... wrong, again.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105421176432011&amp;w=2" xml:lang="en">20030528 MS03-019: DoS or Code of Choice</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-019" xml:lang="en">MS03-019</vuln:reference>
    </vuln:references>
    <vuln:summary>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0228">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:-"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_player:-</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0228</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:13.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A321" name="oval:org.mitre.oval:def:321"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105232913516488&amp;w=2" xml:lang="en">20030507 Windows Media Player directory traversal vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105240528419389&amp;w=2" xml:lang="en">20030508 why i love xs4all + mediaplayer thingie</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105233960728901&amp;w=2" xml:lang="en">20030507 Windows Media Player directory traversal vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/384932" xml:lang="en">VU#384932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7517" xml:lang="en">7517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-017" xml:lang="en">MS03-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11953" xml:lang="en">mediaplayer-skin-code-execution(11953)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0230">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000::desktop_engine"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000::desktop_engine</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp3a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0230</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:33.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A235" name="oval:org.mitre.oval:def:235"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/556356" xml:lang="en">VU#556356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031" xml:lang="en">MS03-031</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0231">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000::desktop_engine"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000::desktop_engine</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp3a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0231</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:34.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A299" name="oval:org.mitre.oval:def:299"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a072303-2.txt" xml:lang="en">A072303-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/918652" xml:lang="en">VU#918652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031" xml:lang="en">MS03-031</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0232">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000::desktop_engine"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000::desktop_engine</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp3a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0232</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:34.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A303" name="oval:org.mitre.oval:def:303"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a072303-3.txt" xml:lang="en">A072303-3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/584868" xml:lang="en">VU#584868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031" xml:lang="en">MS03-031</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0233">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0233</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:35.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1094" name="oval:org.mitre.oval:def:1094"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105120164927952&amp;w=2" xml:lang="en">20030424 Internet Explorer Plugin.ocx heap overflow (#NISR24042003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11854.php" xml:lang="en">ie-plugin-load-bo(11854)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0235">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.15build1701"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.21build1800"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0b_build3278"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3636"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3638"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3659"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3722"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3727"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3777"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3799"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.15build1701</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.21build1800</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0b_build3278</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3636</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3638</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3659</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3722</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3727</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3777</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3799</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0235</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7461" xml:lang="en">7461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11938" xml:lang="en">icq-pop3-format-string(11938)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0236">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.15build1701"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.21build1800"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0b_build3278"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3636"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3638"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3659"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3722"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3727"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3777"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3799"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.15build1701</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.21build1800</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0b_build3278</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3636</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3638</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3659</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3722</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3727</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3777</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3799</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0236</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7462" xml:lang="en">7462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7463" xml:lang="en">7463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11939" xml:lang="en">icq-pop3-email-bo(11939)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0237">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.15build1701"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.21build1800"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0b_build3278"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3636"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3638"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3659"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3722"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3727"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3777"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3799"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.15build1701</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.21build1800</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0b_build3278</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3636</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3638</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3659</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3722</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3727</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3777</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3799</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0237</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7464" xml:lang="en">7464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11944" xml:lang="en">icq-features-no-auth(11944)</vuln:reference>
    </vuln:references>
    <vuln:summary>The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0238">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.15build1701"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.21build1800"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0b_build3278"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3636"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3638"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3659"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3722"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3727"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3777"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3799"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.15build1701</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.21build1800</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0b_build3278</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3636</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3638</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3659</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3722</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3727</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3777</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3799</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0238</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7465" xml:lang="en">7465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11947" xml:lang="en">icq-table-tag-dos(11947)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0239">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.15build1701"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.21build1800"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2000.0b_build3278"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001a"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3636"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3638"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2001b_build3659"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3722"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2002a_build3727"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3777"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3799"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.15build1701</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.21build1800</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2000.0b_build3278</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001a</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3636</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3638</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2001b_build3659</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3722</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2002a_build3727</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3777</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3799</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0239</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2" xml:lang="en">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7466" xml:lang="en">7466</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11948" xml:lang="en">icq-gif89a-header-dos(11948)</vuln:reference>
    </vuln:references>
    <vuln:summary>icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0240">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:axis:2100_network_camera:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2110_network_camera:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2120_network_camera:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2130_ptz_network_camera:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2400_video_server:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2401_video_server:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2420_network_camera:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2460_network_dvr:3.00"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:250s_video_server:3.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:axis:2100_network_camera:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2110_network_camera:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2120_network_camera:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2130_ptz_network_camera:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2400_video_server:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2401_video_server:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2420_network_camera:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2460_network_dvr:3.00</vuln:product>
      <vuln:product>cpe:/h:axis:250s_video_server:3.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0240</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105406374731579&amp;w=2" xml:lang="en">20030527 CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006854" xml:lang="en">1006854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/799060" xml:lang="en">VU#799060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7652" xml:lang="en">7652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12104" xml:lang="en">axis-admin-authentication-bypass(12104)</vuln:reference>
    </vuln:references>
    <vuln:summary>The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0241">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:frontrange:goldmine:5.70"/>
        <cpe-lang:fact-ref name="cpe:/a:frontrange:goldmine:6.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:frontrange:goldmine:5.70</vuln:product>
      <vuln:product>cpe:/a:frontrange:goldmine:6.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0241</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:50.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0091.html" xml:lang="en">20030528 SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnap.net/security/gm001.html" xml:lang="en">http://www.secnap.net/security/gm001.html</vuln:reference>
    </vuln:references>
    <vuln:summary>FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0242">
    <vuln:cve-id>CVE-2003-0242</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006796" xml:lang="en">1006796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/869548" xml:lang="en">VU#869548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7628" xml:lang="en">7628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12027" xml:lang="en">macos-ipsec-acl-bypass(12027)</vuln:reference>
    </vuln:references>
    <vuln:summary>IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0243">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:happycgi:happymall:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:happycgi:happymall:4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:happycgi:happymall:4.3</vuln:product>
      <vuln:product>cpe:/a:happycgi:happymall:4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0243</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:21.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0058.html" xml:lang="en">20030507 Happymall E-Commerce Remote Command Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006707" xml:lang="en">1006707</vuln:reference>
    </vuln:references>
    <vuln:summary>Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0244">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0244</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A261" name="oval:org.mitre.oval:def:261"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0073.html" xml:lang="en">20030517 Algorithmic Complexity Attacks and the Linux Networking Code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105301461726555&amp;w=2" xml:lang="en">ESA-20030515-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105595901923063&amp;w=2" xml:lang="en">20030618 [slackware-security]  2.4.21 kernels available (SSA:2003-168-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=linux-kernel&amp;m=104956079213417" xml:lang="en">http://marc.info/?l=linux-kernel&amp;m=104956079213417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html" xml:lang="en">http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" xml:lang="en">MDKSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" xml:lang="en">MDKSA-2003:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-145.html" xml:lang="en">RHSA-2003:145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-147.html" xml:lang="en">RHSA-2003:147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-172.html" xml:lang="en">RHSA-2003:172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7601" xml:lang="en">7601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15382" xml:lang="en">data-algorithmic-complexity-dos(15382)</vuln:reference>
    </vuln:references>
    <vuln:summary>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0245">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0245</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html" xml:lang="en">20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" xml:lang="en">CLA-2003:661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105418115512559&amp;w=2" xml:lang="en">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/httpd/Announcement2.html" xml:lang="en">http://www.apache.org/dist/httpd/Announcement2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/05.30.03.txt" xml:lang="en">http://www.idefense.com/advisory/05.30.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/757612" xml:lang="en">VU#757612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:063" xml:lang="en">MDKSA-2003:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-186.html" xml:lang="en">RHSA-2003:186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7723" xml:lang="en">7723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12090" xml:lang="en">apache-aprpsprintf-code-execution(12090)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0246">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.63"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.65"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.66"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.67"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.68"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.69"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.58</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.59</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.63</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.65</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.66</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.67</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.68</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.69</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0246</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A278" name="oval:org.mitre.oval:def:278"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html" xml:lang="en">20030520 Linux 2.4 kernel ioperm vuln</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105301461726555&amp;w=2" xml:lang="en">ESA-20030515-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" xml:lang="en">MDKSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" xml:lang="en">MDKSA-2003:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-147.html" xml:lang="en">RHSA-2003:147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-172.html" xml:lang="en">RHSA-2003:172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-41.txt" xml:lang="en">TLSA-2003-41</vuln:reference>
    </vuln:references>
    <vuln:summary>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0247">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0247</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A284" name="oval:org.mitre.oval:def:284"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" xml:lang="en">MDKSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" xml:lang="en">MDKSA-2003:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-187.html" xml:lang="en">RHSA-2003:187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-195.html" xml:lang="en">RHSA-2003:195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-41.txt" xml:lang="en">TLSA-2003-41</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0248">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0248</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A292" name="oval:org.mitre.oval:def:292"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" xml:lang="en">MDKSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" xml:lang="en">MDKSA-2003:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-187.html" xml:lang="en">RHSA-2003:187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-195.html" xml:lang="en">RHSA-2003:195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-41.txt" xml:lang="en">TLSA-2003-41</vuln:reference>
    </vuln:references>
    <vuln:summary>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0249">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0249</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:51.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-01T09:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=97" xml:lang="en">20030625 PHP/Apache .htaccess Authentication Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive.  NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method.  A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods.  It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0251">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nis:ypserv_nis_server:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nis:ypserv_nis_server:2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0251</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:33.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A667" name="oval:org.mitre.oval:def:667"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016517" xml:lang="en">1016517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55600&amp;zone_32=category%3Asecurity" xml:lang="en">55600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:072" xml:lang="en">MDKSA-2003:072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-173.html" xml:lang="en">RHSA-2003:173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-201.html" xml:lang="en">RHSA-2003:201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/440454/100/0/threaded" xml:lang="en">HPSBTU02132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8031" xml:lang="en">8031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-43.txt" xml:lang="en">TLSA-2003-43</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2873" xml:lang="en">ADV-2006-2873</vuln:reference>
    </vuln:references>
    <vuln:summary>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0252">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nfs:nfs-utils:0.2</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:0.2.1</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:0.3.1</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:0.3.3</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0.1</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0252</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:19.990-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A443" name="oval:org.mitre.oval:def:443"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html" xml:lang="en">20030714 Linux nfs-utils xlog() off-by-one bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html" xml:lang="en">20030714 Reality of the rpc.mountd bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105820223707191&amp;w=2" xml:lang="en">20030714 Linux nfs-utils xlog() off-by-one bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105830921519513&amp;w=2" xml:lang="en">20030715 [slackware-security]  nfs-utils packages replaced (SSA:2003-195-01b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839032403325&amp;w=2" xml:lang="en">20030716 Immunix Secured OS 7+ nfs-utils update -- bugtraq</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007187" xml:lang="en">1007187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001262.1-1" xml:lang="en">1001262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-349" xml:lang="en">DSA-349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/258564" xml:lang="en">VU#258564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:076" xml:lang="en">MDKSA-2003:076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_031_nfs_utils.html" xml:lang="en">SuSE-SA:2003:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-206.html" xml:lang="en">RHSA-2003:206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-207.html" xml:lang="en">RHSA-2003:207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8179" xml:lang="en">8179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-44.txt" xml:lang="en">TLSA-2003-44</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12600" xml:lang="en">nfs-utils-offbyone-bo(12600)</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0253">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0253</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A173" name="oval:org.mitre.oval:def:173"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105776593602600&amp;w=2" xml:lang="en">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" xml:lang="en">MDKSA-2003:075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-240.html" xml:lang="en">RHSA-2003:240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0254">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0254</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A183" name="oval:org.mitre.oval:def:183"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105776593602600&amp;w=2" xml:lang="en">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" xml:lang="en">MDKSA-2003:075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-240.html" xml:lang="en">RHSA-2003:240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0255">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0255</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A135" name="oval:org.mitre.oval:def:135"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000694" xml:lang="en">CLA-2003:694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105215110111174&amp;w=2" xml:lang="en">20030504 Key validity bug in GnuPG 1.2.1 and earlier</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105301357425157&amp;w=2" xml:lang="en">ESA-20030515-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105311804129104&amp;w=2" xml:lang="en">20030516 [OpenPKG-SA-2003.029] OpenPKG Security Advisory (gnupg)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105362224514081&amp;w=2" xml:lang="en">20030522 [slackware-security]  GnuPG key validation fix (SSA:2003-141-04)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/397604" xml:lang="en">VU#397604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html" xml:lang="en">20030515-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html" xml:lang="en">http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:061" xml:lang="en">MDKSA-2003:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-175.html" xml:lang="en">RHSA-2003:175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-176.html" xml:lang="en">RHSA-2003:176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7497" xml:lang="en">7497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-34.txt" xml:lang="en">TLSA200334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11930" xml:lang="en">gnupg-invalid-key-acceptance(11930)</vuln:reference>
    </vuln:references>
    <vuln:summary>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0256">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:kopete:0.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:kopete:0.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0256</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:26.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000665" xml:lang="en">CLA-2003:665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2" xml:lang="en">http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:055" xml:lang="en">MDKSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:summary>The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0257">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0257</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:29.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IBM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1" xml:lang="en">MSS-OAR-E01-2003:0660.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12000" xml:lang="en">aix-print-format-string(12000)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0258">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3015_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3030_concentator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3060_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3080_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5%28rel%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.a"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.c"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.d"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7d"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3005_concentrator_software:4.0.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:cisco:vpn_3002_hardware_client"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:vpn_3002_hardware_client</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3015_concentrator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3030_concentator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3060_concentrator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3080_concentrator</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5%28rel%29</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.2</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.3</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.5</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.3</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.5</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.a</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.b</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.c</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.d</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7d</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:4.0</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3005_concentrator_software:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0258</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:19.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" xml:lang="en">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/727780" xml:lang="en">VU#727780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11954" xml:lang="en">cisco-vpn-unauth-access(11954)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0259">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3015_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3030_concentator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3060_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3080_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.a"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.c"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.d"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.f"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.a"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1%28rel%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5%28rel%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.a"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.c"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.d"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7d"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:cisco:vpn_3002_hardware_client"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:vpn_3002_hardware_client</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3015_concentrator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3030_concentator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3060_concentrator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3080_concentrator</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.0</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.a</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.b</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.c</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.d</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.f</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.a</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.b</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1%28rel%29</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.2</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5%28rel%29</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.2</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.3</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.5</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.3</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.5</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.a</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.b</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.c</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7.d</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0259</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:19.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" xml:lang="en">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/317348" xml:lang="en">VU#317348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11955" xml:lang="en">cisco-vpn-ssh-dos(11955)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0260">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3015_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3030_concentator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3060_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:vpn_3080_concentrator"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.a"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.c"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.d"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.f"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.a"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1%28rel%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5%28rel%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:cisco:vpn_3002_hardware_client"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:vpn_3002_hardware_client</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3015_concentrator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3030_concentator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3060_concentrator</vuln:product>
      <vuln:product>cpe:/h:cisco:vpn_3080_concentrator</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.0</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.a</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.b</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.c</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.d</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:2.5.2.f</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.a</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.3.b</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.0.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1%28rel%29</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.2</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.1.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5%28rel%29</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.2</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.3</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.4</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.5.5</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.3</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.5</vuln:product>
      <vuln:product>cpe:/o:cisco:vpn_3000_concentrator_series_software:3.6.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0260</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:19.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" xml:lang="en">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/221164" xml:lang="en">VU#221164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11956" xml:lang="en">cisco-vpn-icmp-dos(11956)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0261">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fuzz:fuzz:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fuzz:fuzz:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0261</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:26.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-302" xml:lang="en">DSA-302</vuln:reference>
    </vuln:references>
    <vuln:summary>fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0262">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:leksbot:leksbot:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:leksbot:leksbot:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0262</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-299" xml:lang="en">DSA-299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7505" xml:lang="en">7505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11945" xml:lang="en">kataxwr-gain-privileges(11945)</vuln:reference>
    </vuln:references>
    <vuln:summary>leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0263">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:floosietek:ftgatepro:1.22_1328"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:floosietek:ftgatepro:1.22_1328</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0263</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0052.html" xml:lang="en">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105223471822836&amp;w=2" xml:lang="en">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7506" xml:lang="en">7506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7508" xml:lang="en">7508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11951" xml:lang="en">ftgate-mailfrom-rcptto-bo(11951)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0264">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:seattle_lab_software:slmail:5.1.0.4420"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:seattle_lab_software:slmail:5.1.0.4420</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0264</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:21.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105232506011335&amp;w=2" xml:lang="en">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105233360321895&amp;w=2" xml:lang="en">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/slmail-vulns.txt" xml:lang="en">http://www.nextgenss.com/advisories/slmail-vulns.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0265">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.3.29"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.3.7_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.3.29</vuln:product>
      <vuln:product>cpe:/a:sap:sap_db:7.4.3.7_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0265</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:23.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105232424810097&amp;w=2" xml:lang="en">20030507 SAP database local root vulnerability during installation. (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7421" xml:lang="en">7421</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0266">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bvrp_software:slwebmail:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bvrp_software:slwebmail:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0266</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:24.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105232436210273&amp;w=2" xml:lang="en">20030507 Multiple Vulnerabilities in SLWebmail</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" xml:lang="en">20030507 Multiple Vulnerabilities in SLWebmail</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" xml:lang="en">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0267">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bvrp_software:slwebmail:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bvrp_software:slwebmail:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0267</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:26.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105232436210273&amp;w=2" xml:lang="en">20030507 Multiple Vulnerabilities in SLWebmail</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" xml:lang="en">20030507 Multiple Vulnerabilities in SLWebmail</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" xml:lang="en">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0268">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bvrp_software:slwebmail:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bvrp_software:slwebmail:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0268</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:27.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105232436210273&amp;w=2" xml:lang="en">20030507 Multiple Vulnerabilities in SLWebmail</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" xml:lang="en">20030507 Multiple Vulnerabilities in SLWebmail</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" xml:lang="en">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0269">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:youbin:youbin:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:youbin:youbin:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:youbin:youbin:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:youbin:youbin:2.5</vuln:product>
      <vuln:product>cpe:/a:youbin:youbin:3.0</vuln:product>
      <vuln:product>cpe:/a:youbin:youbin:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0269</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0053.html" xml:lang="en">20030506 youbin local root exploit + advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004892.html" xml:lang="en">20030506 youbin local root exploit + advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105223947528794&amp;w=2" xml:lang="en">20030506 youbin local root exploit + advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7503" xml:lang="en">7503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11949" xml:lang="en">youbin-home-bo(11949)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0270">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:apple:802.11n:7.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:apple:802.11n:7.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0270</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006742" xml:lang="en">1006742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a051203-1.txt" xml:lang="en">A051203-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7554" xml:lang="en">7554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11980" xml:lang="en">airport-auth-credentials-disclosure(11980)</vuln:reference>
    </vuln:references>
    <vuln:summary>The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0271">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cooolsoft:personal_ftp_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cooolsoft:personal_ftp_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0271</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:29.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105240469318622&amp;w=2" xml:lang="en">20030508 Remote Stack Overflow exploit for Personal FTPD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.nnov.ru/search/document.asp?docid=4309" xml:lang="en">http://security.nnov.ru/search/document.asp?docid=4309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316958" xml:lang="en">20030331 Personal FTP Server</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0272">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:miniportal:miniportal:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:miniportal:miniportal:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:miniportal:miniportal:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miniportal:miniportal:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miniportal:miniportal:1.9</vuln:product>
      <vuln:product>cpe:/a:miniportal:miniportal:2.0</vuln:product>
      <vuln:product>cpe:/a:miniportal:miniportal:2.1</vuln:product>
      <vuln:product>cpe:/a:miniportal:miniportal:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0272</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:31.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105240907024660&amp;w=2" xml:lang="en">20030508 miniPortail (PHP) : Admin Access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.frog-man.org/tutos/miniPortail.txt" xml:lang="en">http://www.frog-man.org/tutos/miniPortail.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0273">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:best_practical_solutions:request_tracker:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.0</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.1</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.2</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.3</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.4</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.5</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.6</vuln:product>
      <vuln:product>cpe:/a:best_practical_solutions:request_tracker:1.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0273</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:32.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html" xml:lang="en">http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105240947225275&amp;w=2" xml:lang="en">20030508 Fw: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0274">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cren:listproc:8.2.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cren:listproc:8.2.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0274</vuln:cve-id>
    <vuln:published-datetime>2003-05-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:33.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105241224228693&amp;w=2" xml:lang="en">20030508 SRT2003-05-08-1137 - ListProc mailing list ULISTPROC_UMASK overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0275">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yabb:yabb:1.5.2::second_edition"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yabb:yabb:1.5.2::second_edition</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0275</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:34.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105249980809988&amp;w=2" xml:lang="en">20030509 II-Labs Advisory: Remote code execution in YaBBse 1.5.2 (php version)</vuln:reference>
    </vuln:references>
    <vuln:summary>SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0276">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pi3:pi3web:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pi3:pi3web:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0276</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105155818012718&amp;w=2" xml:lang="en">20030428 Pi3Web 2.0.1 DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105275789410250&amp;w=2" xml:lang="en">20030512 Unix Version of the Pi3web DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7555" xml:lang="en">7555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11889" xml:lang="en">pi3web-get-request-bo(11889)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0277">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:happycgi:happymall:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:happycgi:happymall:4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:happycgi:happymall:4.3</vuln:product>
      <vuln:product>cpe:/a:happycgi:happymall:4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0277</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105276130814262&amp;w=2" xml:lang="en">20030512 One more flaw in Happymall</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7559" xml:lang="en">7559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11987" xml:lang="en">happymall-dotdot-directory-traversal(11987)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0278">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:happycgi.com:happymall:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:happycgi.com:happymall:4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:happycgi.com:happymall:4.3</vuln:product>
      <vuln:product>cpe:/a:happycgi.com:happymall:4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0278</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105276130814262&amp;w=2" xml:lang="en">20030512 One more flaw in Happymall</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7557" xml:lang="en">7557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11988" xml:lang="en">happymall-normalhtml-xss(11988)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0279">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.0</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0279</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html" xml:lang="en">20030513 More and More SQL injection on PHP-Nuke 6.5.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105276019312980&amp;w=2" xml:lang="en">20030512 Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7558" xml:lang="en">7558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7588" xml:lang="en">7588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11984" xml:lang="en">phpnuke-web-sql-injection(11984)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0280">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:youngzsoft:cmailserver:4.0.2003.23.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:youngzsoft:cmailserver:4.0.2003.23.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0280</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html" xml:lang="en">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105258772101349&amp;w=2" xml:lang="en">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7547" xml:lang="en">7547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7548" xml:lang="en">7548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11975" xml:lang="en">cmailserver-smtp-bo(11975)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0281">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:firebirdsql:firebird:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:firebirdsql:firebird:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0281</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105259012802997&amp;w=2" xml:lang="en">20030509 Firebird Local exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://seclists.org/lists/bugtraq/2002/Jun/0212.html" xml:lang="en">20020617 Interbase 6.0 malloc() issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-18.xml" xml:lang="en">GLSA-200405-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7546" xml:lang="en">7546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11977" xml:lang="en">firebird-interbase-bo(11977)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0282">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:openlinux_server:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openlinux_workstation:3.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:info-zip:unzip:5.50</vuln:product>
      <vuln:product>cpe:/o:sco:openlinux_server:3.1.1</vuln:product>
      <vuln:product>cpe:/o:sco:openlinux_workstation:3.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0282</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A619" name="oval:org.mitre.oval:def:619"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt" xml:lang="en">CSSA-2003-031.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000672" xml:lang="en">CLA-2003:672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01" xml:lang="en">IMNX-2003-7+-017-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105259038503175&amp;w=2" xml:lang="en">20030509 unzip directory traversal revisited</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105786446329347&amp;w=2" xml:lang="en">20030710 [OpenPKG-SA-2003.033] OpenPKG Security Advisory (infozip)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-111.shtml" xml:lang="en">N-111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-344" xml:lang="en">DSA-344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.info-zip.org/FAQ.html" xml:lang="en">http://www.info-zip.org/FAQ.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:073" xml:lang="en">MDKSA-2003:073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-199.html" xml:lang="en">RHSA-2003:199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-200.html" xml:lang="en">RHSA-2003:200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7550" xml:lang="en">7550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-42.txt" xml:lang="en">TLSA-2003-42</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12004" xml:lang="en">unzip-dotdot-directory-traversal(12004)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0283">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0283</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105251043821533&amp;w=2" xml:lang="en">20030509 A Phorum's bug...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105251421925394&amp;w=2" xml:lang="en">20030509 Re: A Phorum's bug...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7545" xml:lang="en">7545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11974" xml:lang="en">phorum-message-html-injection(11974)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "&lt;&lt;" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0284">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0284</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:57.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121" xml:lang="en">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/184820" xml:lang="en">VU#184820</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0285">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0285</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105284689228961&amp;w=2" xml:lang="en">20030513 AIX sendmail open relay</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt" xml:lang="en">http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/814617" xml:lang="en">VU#814617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7580" xml:lang="en">7580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11993" xml:lang="en">aix-sendmail-mail-relay(11993)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0286">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0286</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html" xml:lang="en">20030512 Snitz Forum 3.3.03 Remote Command Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105277599131134&amp;w=2" xml:lang="en">20030513 Snitz Forum 3.3.03 Remote Command Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0305-exploits/snitz_exec.txt" xml:lang="en">http://packetstormsecurity.org/0305-exploits/snitz_exec.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/35764" xml:lang="en">35764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7549" xml:lang="en">7549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11981" xml:lang="en">snitz-register-sql-injection(11981)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0287">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:six_apart:movable_type:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:six_apart:movable_type:2.63"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:six_apart:movable_type:2.6</vuln:product>
      <vuln:product>cpe:/a:six_apart:movable_type:2.63</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0287</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105276879622636&amp;w=2" xml:lang="en">20030512 CSS found in Movable Type</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105277690132079&amp;w=2" xml:lang="en">20030512 Re: CSS found in Movable Type</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105284589927655&amp;w=2" xml:lang="en">20030513 Re: CSS found in Movable Type -- Nope</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7560" xml:lang="en">7560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12003" xml:lang="en">movable-type-comment-xss(12003)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0288">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hiroaki_shirouzu:ip_messenger:2.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hiroaki_shirouzu:ip_messenger:2.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0288</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105283843417610&amp;w=2" xml:lang="en">20030513 [SNS Advisory No.64] IP Messenger for Win Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lac.co.jp/security/english/snsadv_e/64_e.html" xml:lang="en">http://www.lac.co.jp/security/english/snsadv_e/64_e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7566" xml:lang="en">7566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11986" xml:lang="en">ip-messenger-filename-bo(11986)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the file &amp; folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0289">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cdrtools:cdrecord:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:cdrtools:cdrecord:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cdrtools:cdrecord:1.11</vuln:product>
      <vuln:product>cpe:/a:cdrtools:cdrecord:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0289</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:30.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz" xml:lang="en">ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://forums.gentoo.org/viewtopic.php?t=54904" xml:lang="en">200305-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105285564307225&amp;w=2" xml:lang="en">20030513 cdrtools2.0 Format String Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105286031812533&amp;w=2" xml:lang="en">20030513 Cdrecord_local_root_exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:058" xml:lang="en">MDKSA-2003:058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/5ZP0C2AAAC.html" xml:lang="en">http://www.securiteam.com/exploits/5ZP0C2AAAC.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7565" xml:lang="en">7565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12007" xml:lang="en">cdrtools-scsiopen-format-string(12007)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0290">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.9x"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:etype:eserv:2.9x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0290</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0064.html" xml:lang="en">20030511 eServ Memory Leak Enables Denial of Service Attacks</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105284630228137&amp;w=2" xml:lang="en">20030511 eServ Memory Leak Enables Denial of Service Attacks</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105284631428187&amp;w=2" xml:lang="en">20030513 eServ Memory Leak Solution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7552" xml:lang="en">7552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11973" xml:lang="en">eserv-multiple-connections-dos(11973)</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0291">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:3com:3cp4144:1.1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:3com:3cp4144:1.1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0291</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105292451702516&amp;w=2" xml:lang="en">20030514 Memory leak in 3COM 812 DSL routers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105301488426951&amp;w=2" xml:lang="en">20030515 RE : Memory leak in 3COM DSL routers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm" xml:lang="en">http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7592" xml:lang="en">7592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11999" xml:lang="en">3com-officeconnect-memory-leak(11999)</vuln:reference>
    </vuln:references>
    <vuln:summary>3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0292">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:inktomi:inktomi_traffic-server:5.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:inktomi:inktomi_traffic-server:5.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0292</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:55.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105292750807005&amp;w=2" xml:lang="en">20030514 Inktomi Traffic-Server XSS: man-in-the-middle XSS !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7596" xml:lang="en">7596</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0293">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:palm:palmos"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:palm:palmos</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0293</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:56.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105293128612131&amp;w=2" xml:lang="en">20030514 PalmOS ICMP flood DoS.</vuln:reference>
    </vuln:references>
    <vuln:summary>PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0294">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php-proxima:php-proxima:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php-proxima:php-proxima:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0294</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:58.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105293834421549&amp;w=2" xml:lang="en">20030514 php-proxima Remote File Access Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0295">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.0_beta_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.0_beta_2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0295</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:31:59.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105292832607981&amp;w=2" xml:lang="en">20030514 VBulletin Preview Message - XSS Vuln</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105293890422210&amp;w=2" xml:lang="en">20030514 Re: VBulletin Preview Message - XSS Vuln</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0296">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0296</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:00.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0297">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:c-client"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:imap-2002b"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.53"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:c-client</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:imap-2002b</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.53</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0297</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:35.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-015.html" xml:lang="en">RHSA-2005:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-114.html" xml:lang="en">RHSA-2005:114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/430302/100/0/threaded" xml:lang="en">FLSA:184074</vuln:reference>
    </vuln:references>
    <vuln:summary>c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0298">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0298</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:02.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0299">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stuart_parmenter:balsa:2.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.4.1</vuln:product>
      <vuln:product>cpe:/a:stuart_parmenter:balsa:2.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0299</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:04.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0300">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:6.00.2800.1106"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora:5.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stuart_parmenter:balsa:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:sylpheed:sylpheed_email_client:0.8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.53"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook_express:6.00.2800.1106</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.4.1</vuln:product>
      <vuln:product>cpe:/a:qualcomm:eudora:5.2.1</vuln:product>
      <vuln:product>cpe:/a:stuart_parmenter:balsa:2.0.10</vuln:product>
      <vuln:product>cpe:/a:sylpheed:sylpheed_email_client:0.8.11</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.53</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0300</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:05.313-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0301">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:6.00.2800.1106"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook_express:6.00.2800.1106</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0301</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:06.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0302">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora:5.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:eudora:5.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0302</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:07.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2" xml:lang="en">20030514 Buffer overflows in multiple IMAP clients</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0303">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oneorzero:oneorzero_helpdesk:1.4_rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oneorzero:oneorzero_helpdesk:1.4_rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0303</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:08.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" xml:lang="en">20030515 OneOrZero Security Problems (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105302025601231&amp;w=2" xml:lang="en">20030515 OneOrZero Security Problems (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7609" xml:lang="en">7609</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0304">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oneorzero:oneorzero_helpdesk:1.4_rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oneorzero:oneorzero_helpdesk:1.4_rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0304</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:10.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" xml:lang="en">20030515 OneOrZero Security Problems (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105302025601231&amp;w=2" xml:lang="en">20030515 OneOrZero Security Problems (PHP)</vuln:reference>
    </vuln:references>
    <vuln:summary>one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0305">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2819%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2819%29sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2819%29sp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2820%29sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2820%29sp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2821%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2821%29sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2821%29sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%288%29ea"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%289%29ea"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810%29e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810%29ec"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810%29ex"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810%29ey"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810.5%29ec"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2810a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811.5%29e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2812%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2812a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2812b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2812c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2813%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2814%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2814.5%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%286.8a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%287%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%287%29da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%287a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%287b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%287c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%289%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%289.4%29da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2810.5%29s"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2819%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2819%29sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2819%29sp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2820%29sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2820%29sp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2821%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2821%29sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2821%29sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%288%29ea</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%289%29ea</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810%29e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810%29ec</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810%29ex</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810%29ey</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810.5%29ec</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2810a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811.5%29e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2812%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2812a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2812b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2812c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2813%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2814%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2814.5%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%286.8a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%287%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%287%29da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%287a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%287b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%287c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%289%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%289.4%29da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2810.5%29s</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0305</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:08.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5608" name="oval:org.mitre.oval:def:5608"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030515-saa.shtml" xml:lang="en">20030515 Cisco Security Advisory: Cisco IOS Software Processing of SAA Packets</vuln:reference>
    </vuln:references>
    <vuln:summary>The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0306">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0306</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:35.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3095" name="oval:org.mitre.oval:def:3095"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105284486526310&amp;w=2" xml:lang="en">20030511 Detailed analysis: Buffer overflow in Explorer.exe on Windows XP SP1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105301349925036&amp;w=2" xml:lang="en">20030515 Re[2]: EXPLOIT: Buffer overflow in Explorer.exe on Windows XP SP1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://marc.info/?l=vuln-dev&amp;m=105241032526289&amp;w=2" xml:lang="en">20030507 Buffer overflow in Explorer.exe</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-027" xml:lang="en">MS03-027</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0307">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:poster:poster:version.two"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:poster:poster:version.two</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0307</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:12.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105295155004969&amp;w=2" xml:lang="en">20030514 [VULNERABILITY] PHP 'poster version.two'</vuln:reference>
    </vuln:references>
    <vuln:summary>Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0308">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.9</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0308</vuln:cve-id>
    <vuln:published-datetime>2003-05-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-11T00:29:40.900-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/496408" xml:lang="en">http://bugs.debian.org/496408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base" xml:lang="en">http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-305" xml:lang="en">DSA-305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2008/10/30/2" xml:lang="en">[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.gentoo.org/show_bug.cgi?id=235770" xml:lang="en">https://bugs.gentoo.org/show_bug.cgi?id=235770</vuln:reference>
    </vuln:references>
    <vuln:summary>The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0309">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0.2800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0.2800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0309</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:36.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A948" name="oval:org.mitre.oval:def:948"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105249399103214&amp;w=2" xml:lang="en">20030508 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! [CRITICAL]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105294081325040&amp;w=2" xml:lang="en">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105294162726096&amp;w=2" xml:lang="en">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/251788" xml:lang="en">VU#251788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7539" xml:lang="en">7539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-020" xml:lang="en">MS03-020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12019" xml:lang="en">ie-frame-restrictions-bypass(12019)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0310">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ez:ez_publish:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ez:ez_publish:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0310</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:15.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105310013606680&amp;w=2" xml:lang="en">20030516 EzPublish Directory XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0312">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snowblind.net:snowblind_web_server:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snowblind.net:snowblind_web_server:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0312</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:16.457-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2" xml:lang="en">20030516 Snowblind Web Server: multiple issues</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0313">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snowblind.net:snowblind_web_server:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snowblind.net:snowblind_web_server:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0313</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:17.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2" xml:lang="en">20030516 Snowblind Web Server: multiple issues</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0314">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snowblind.net:snowblind_web_server:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snowblind.net:snowblind_web_server:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0314</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:18.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2" xml:lang="en">20030516 Snowblind Web Server: multiple issues</vuln:reference>
    </vuln:references>
    <vuln:summary>Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "&lt;/" sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0315">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snowblind.net:snowblind_web_server:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snowblind.net:snowblind_web_server:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0315</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:19.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2" xml:lang="en">20030516 Snowblind Web Server: multiple issues</vuln:reference>
    </vuln:references>
    <vuln:summary>Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0316">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fourelle_venturi_wireless:venturi_client:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fourelle_venturi_wireless:venturi_client:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0316</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:01.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0188.html" xml:lang="en">20030516 Venturi Client 2.1 confirmed as open relay [Verizon Wireless Mobile Office]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm" xml:lang="en">http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0317">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:iisprotect:iisprotect:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:iisprotect:iisprotect:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:iisprotect:iisprotect:2.1</vuln:product>
      <vuln:product>cpe:/a:iisprotect:iisprotect:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0317</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-03T00:20:39.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=25" xml:lang="en">20030522 Authentication Bypass in iisPROTECT</vuln:reference>
    </vuln:references>
    <vuln:summary>iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0318">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0318</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:21.520-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105319538308834&amp;w=2" xml:lang="en">20030517 PHP-Nuke code injection in Yearly Stats at Statistics module</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0319">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smartmax_software:mailmax:5.0.10.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smartmax_software:mailmax:5.0.10.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0319</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:22.863-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0072.html" xml:lang="en">20030517 Buffer overflow vulnerability found in MailMax version 5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105319299407291&amp;w=2" xml:lang="en">20030517 Buffer overflow vulnerability found in MailMax version 5</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0320">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andy_prevost:ttcms:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andy_prevost:ttcms:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0320</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:23.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105320172212990&amp;w=2" xml:lang="en">20030517 Remote code execution in ttCMS &lt;=v2.3</vuln:reference>
    </vuln:references>
    <vuln:summary>header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0321">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:colten_edwards:bitchx:1.0.0c19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:colten_edwards:bitchx:1.0.0c19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0321</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:25.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" xml:lang="en">CLA-2003:655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104766521328322&amp;w=2" xml:lang="en">20030313 Buffer overflows in ircII-based clients</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104852615211913&amp;w=2" xml:lang="en">20030324 GLSA:  bitchx (200303-21)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" xml:lang="en">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-306" xml:lang="en">DSA-306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7096" xml:lang="en">7096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7097" xml:lang="en">7097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7099" xml:lang="en">7099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7100" xml:lang="en">7100</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled by the functions (1) send_ctcp, (2) cannot_join_channel, (3) cluster, (4) BX_compress_modes, (5) handle_oper_vision, and (6) ban_it.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0322">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:colten_edwards:bitchx:1.0.0c19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:colten_edwards:bitchx:1.0.0c19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0322</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:02.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" xml:lang="en">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-306" xml:lang="en">DSA-306</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0323">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_sandrof:ircii:2002-09-12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_sandrof:ircii:2002-09-12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0323</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:26.613-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104766521328322&amp;w=2" xml:lang="en">20030313 Buffer overflows in ircII-based clients</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104808915402926&amp;w=2" xml:lang="en">20030319 [OpenPKG-SA-2003.024] OpenPKG Security Advisory (ircii)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-291" xml:lang="en">DSA-291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-298" xml:lang="en">DSA-298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7098" xml:lang="en">7098</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0324">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epic:epic4:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epic:epic4:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0324</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:27.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104766521328322&amp;w=2" xml:lang="en">20030313 Buffer overflows in ircII-based clients</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-287" xml:lang="en">DSA-287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7091" xml:lang="en">7091</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0325">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ambrosia_software:maelstrom:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ambrosia_software:maelstrom:3.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ambrosia_software:maelstrom:3.0.5</vuln:product>
      <vuln:product>cpe:/a:ambrosia_software:maelstrom:3.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0325</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:29.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105337792703887&amp;w=2" xml:lang="en">20030518 Maelstrom Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105344501331344&amp;w=2" xml:lang="en">20030519 Maelstrom exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105346309123217&amp;w=2" xml:lang="en">20030520 Maelstrom Local Buffer Overflow Exploit, FreeBSD 4.8 edition</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0326">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:slocate:slocate</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0326</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:30.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105337692202626&amp;w=2" xml:lang="en">20030519 bazarr slocate</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7629" xml:lang="en">7629</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0327">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0327</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106936096103805&amp;w=2" xml:lang="en">20031120 R7-0016: Sybase ASE 12.5 Remote Password Array Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0016.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13800" xml:lang="en">sybase-passwordarray-bo(13800)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0328">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epic:epic4:pre2.002"/>
        <cpe-lang:fact-ref name="cpe:/a:epic:epic4:pre2.003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epic:epic4:pre2.002</vuln:product>
      <vuln:product>cpe:/a:epic:epic4:pre2.003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0328</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:03.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1" xml:lang="en">ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-306" xml:lang="en">DSA-306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-399" xml:lang="en">DSA-399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-342.html" xml:lang="en">RHSA-2003:342</vuln:reference>
    </vuln:references>
    <vuln:summary>EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aclogic:cesarftp:0.99g"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aclogic:cesarftp:0.99g</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0329</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:33.020-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0074.html" xml:lang="en">20030520 Plaintext Password in Settings.ini of CesarFTP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105344578100315&amp;w=2" xml:lang="en">20030520 Plaintext Password in Settings.ini of CesarFTP</vuln:reference>
    </vuln:references>
    <vuln:summary>CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0330">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ambrosia_software:maelstrom"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ambrosia_software:maelstrom</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0330</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:34.303-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105344891005369&amp;w=2" xml:lang="en">20030520 Maelstrom Local Buffer Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008832" xml:lang="en">1008832</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0331">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ttcms:ttforum:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ttcms:ttforum:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0331</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:35.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105345273210334&amp;w=2" xml:lang="en">20030520 More vulnerabilities in ttForum/ttCMS -> SQL injection</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0332">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:working_resources_inc.:badblue:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:working_resources_inc.:badblue:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0332</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:36.880-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html" xml:lang="en">20030520 BadBlue Remote Administrative Interface Access Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105346382524169&amp;w=2" xml:lang="en">20030520 BadBlue Remote Administrative Interface Access Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0333">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0333</vuln:cve-id>
    <vuln:published-datetime>2003-05-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105189670912220&amp;w=2" xml:lang="en">20030502 HP-UX 11.0 /usr/bin/kermit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105190667523456&amp;w=2" xml:lang="en">20030502 Re: from bugtraq: HP-UX 11.0 /usr/bin/kermit (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/971364" xml:lang="en">VU#971364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7627" xml:lang="en">7627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11929" xml:lang="en">hp-ckermit-bo(11929)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0334">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:colten_edwards:bitchx:1.0c20cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:colten_edwards:bitchx:1.0c20cvs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0334</vuln:cve-id>
    <vuln:published-datetime>2003-05-10T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" xml:lang="en">CLA-2003:655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105259643606984&amp;w=2" xml:lang="en">20030510 BitchX: Crash when channel modes change</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:069" xml:lang="en">MDKSA-2003:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7551" xml:lang="en">7551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12008" xml:lang="en">bitchx-mode-change-dos(12008)</vuln:reference>
    </vuln:references>
    <vuln:summary>BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0335">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0335</vuln:cve-id>
    <vuln:published-datetime>2003-05-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:40.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105361968110719&amp;w=2" xml:lang="en">20030522 [slackware-security]  quotacheck security fix in rc.M (SSA:2003-141-06)</vuln:reference>
    </vuln:references>
    <vuln:summary>rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0336">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora:5.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:eudora:5.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0336</vuln:cve-id>
    <vuln:published-datetime>2003-05-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:41.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105362278914731&amp;w=2" xml:lang="en">20030522 Eudora 5.2.1 attachment spoof</vuln:reference>
    </vuln:references>
    <vuln:summary>Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly handled by Eudora.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0337">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:platform:lsadmin:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:platform:lsadmin:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0337</vuln:cve-id>
    <vuln:published-datetime>2003-05-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:43.037-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105361879109409&amp;w=2" xml:lang="en">20030522 Security advisory: LSF 5.1 local root exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0338">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_daemon:0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_daemon:0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_daemon:0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wsmp3:wsmp3_daemon:0.0.8</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_daemon:0.0.9</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_daemon:0.0.10</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.1</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.2</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.3</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.4</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.5</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.6</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0338</vuln:cve-id>
    <vuln:published-datetime>2003-05-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:44.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0077.html" xml:lang="en">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105353168619211&amp;w=2" xml:lang="en">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0339">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_daemon:0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_daemon:0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_daemon:0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:wsmp3:wsmp3_web_server:0.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wsmp3:wsmp3_daemon:0.0.8</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_daemon:0.0.9</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_daemon:0.0.10</vuln:product>
      <vuln:product>cpe:/a:wsmp3:wsmp3_web_server:0.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0339</vuln:cve-id>
    <vuln:published-datetime>2003-05-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:45.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105353178019353&amp;w=2" xml:lang="en">20030521 Remote Heap Corruption Overflow vulnerability in WsMp3d.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105361764807746&amp;w=2" xml:lang="en">20030522 WsMp3d remote exploit.</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0340">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:demarc_security:puresecure:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:demarc_security:puresecure:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0340</vuln:cve-id>
    <vuln:published-datetime>2003-05-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:04.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-25T10:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0230.html" xml:lang="en">20030521 Demarc Puresecure v1.6 - Plaintext password issue -</vuln:reference>
    </vuln:references>
    <vuln:summary>Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0341">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:owl:owl_intranet_engine:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:owl:owl_intranet_engine:0.71"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:owl:owl_intranet_engine:0.7</vuln:product>
      <vuln:product>cpe:/a:owl:owl_intranet_engine:0.71</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0341</vuln:cve-id>
    <vuln:published-datetime>2003-05-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:46.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105353266220520&amp;w=2" xml:lang="en">20030521 [AP] Owl Intranet Engine CSS Bug</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0342">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:selom_ofori:blackmoon_ftp_server:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:selom_ofori:blackmoon_ftp_server:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0342</vuln:cve-id>
    <vuln:published-datetime>2003-05-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:48.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105353283720837&amp;w=2" xml:lang="en">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</vuln:reference>
    </vuln:references>
    <vuln:summary>BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0343">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:selom_ofori:blackmoon_ftp_server:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:selom_ofori:blackmoon_ftp_server:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0343</vuln:cve-id>
    <vuln:published-datetime>2003-05-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:32:49.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105353283720837&amp;w=2" xml:lang="en">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</vuln:reference>
    </vuln:references>
    <vuln:summary>BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0344">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0::windows_server_2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0::windows_server_2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0344</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:37.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A922" name="oval:org.mitre.oval:def:922"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006401.html" xml:lang="en">20030709 IE Object Type Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105476381609135&amp;w=2" xml:lang="en">20030604 Internet Explorer Object Type Property Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20030604.html" xml:lang="en">AD20030604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/679556" xml:lang="en">VU#679556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-020" xml:lang="en">MS03-020</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0345">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server_alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server_alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0345</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A118" name="oval:org.mitre.oval:def:118"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A146" name="oval:org.mitre.oval:def:146"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3391" name="oval:org.mitre.oval:def:3391"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007154" xml:lang="en">1007154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/337764" xml:lang="en">VU#337764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8152" xml:lang="en">8152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-024" xml:lang="en">MS03-024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12544" xml:lang="en">win-smb-bo(12544)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0346">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:7.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:directx:5.2</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:6.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:7.0a</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0346</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:39.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1095" name="oval:org.mitre.oval:def:1095"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1104" name="oval:org.mitre.oval:def:1104"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A218" name="oval:org.mitre.oval:def:218"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105899759824008&amp;w=2" xml:lang="en">20030723 EEYE: Windows MIDI Decoder (QUARTZ.DLL) Heap Corruption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-18.html" xml:lang="en">CA-2003-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/265232" xml:lang="en">VU#265232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/561284" xml:lang="en">VU#561284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-030" xml:lang="en">MS03-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0347">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:5.0::sdk"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:6.2::sdk"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:6.3::sdk"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002::professional</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:5.0::sdk</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:6.2</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:6.2::sdk</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:6.3::sdk</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0347</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:40.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.html" xml:lang="en">20030903 EEYE: VBE Document Property Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106262077829157&amp;w=2" xml:lang="en">20030903 EEYE: VBE Document Property Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/804780" xml:lang="en">VU#804780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8534" xml:lang="en">8534</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-037" xml:lang="en">MS03-037</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0348">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_player:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0348</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:40.693-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/320516" xml:lang="en">VU#320516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8034" xml:lang="en">8034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-021" xml:lang="en">MS03-021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12440" xml:lang="en">mediaplayer-activex-obtain-information(12440)</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0349">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0349</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:41.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A938" name="oval:org.mitre.oval:def:938"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105665030925504&amp;w=2" xml:lang="en">20030626 Windows Media Services Remote Command Execution #2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007059" xml:lang="en">1007059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/113716" xml:lang="en">VU#113716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0306&amp;L=NTBUGTRAQ&amp;P=R4563" xml:lang="en">20030626 Windows Media Services Remote Command Execution #2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-022" xml:lang="en">MS03-022</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0350">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0350</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A451" name="oval:org.mitre.oval:def:451"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0015.html" xml:lang="en">20030709 Microsoft Utility Manager Local Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105777681615939&amp;w=2" xml:lang="en">20030709 Microsoft Utility Manager Local Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/utilitymanager.txt" xml:lang="en">http://www.ngssoftware.com/advisories/utilitymanager.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8154" xml:lang="en">8154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-025" xml:lang="en">MS03-025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12543" xml:lang="en">win2k-accessibility-gain-privileges(12543)</vuln:reference>
    </vuln:references>
    <vuln:summary>The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0351">
    <vuln:cve-id>CVE-2003-0351</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:42.133-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0306.  Reason: This candidate is a reservation duplicate of CVE-2003-0306.  Notes: All CVE users should reference CVE-2003-0306 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0352">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0352</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A194" name="oval:org.mitre.oval:def:194"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2343" name="oval:org.mitre.oval:def:2343"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A296" name="oval:org.mitre.oval:def:296"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007079.html" xml:lang="en">20030726 Re: The French BUGTRAQ (New Win RPC Exploit)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007357.html" xml:lang="en">20030730 rpcdcom Universal offsets</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105838687731618&amp;w=2" xml:lang="en">20030716 [LSD] Critical security vulnerability in Microsoft Operating Systems</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105914789527294&amp;w=2" xml:lang="en">20030725 The  Analysis  of LSD's Buffer Overrun in Windows RPC Interface(code revised )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-16.html" xml:lang="en">CA-2003-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-19.html" xml:lang="en">CA-2003-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/568148" xml:lang="en">VU#568148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8205" xml:lang="en">8205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.xfocus.org/documents/200307/2.html" xml:lang="en">http://www.xfocus.org/documents/200307/2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-026" xml:lang="en">MS03-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12629" xml:lang="en">win-rpc-dcom-bo(12629)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0353">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.1.1.3711.11:ga"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.5:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.6:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.6:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.6:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.7:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.12.4202.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:data_access_components:1.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.1.1.3711.11:ga</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.5:gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.6</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.6:gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.6:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.7</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.7:gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.12.4202.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0353</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:44.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1039" name="oval:org.mitre.oval:def:1039"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6954" name="oval:org.mitre.oval:def:6954"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A961" name="oval:org.mitre.oval:def:961"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A962" name="oval:org.mitre.oval:def:962"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106149556627778&amp;w=2" xml:lang="en">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106251069107953&amp;w=2" xml:lang="en">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8455" xml:lang="en">8455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-033" xml:lang="en">MS03-033</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0354">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0354</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A133" name="oval:org.mitre.oval:def:133"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105465818929172&amp;w=2" xml:lang="en">20030603 [OpenPKG-SA-2003.030] OpenPKG Security Advisory (ghostscript)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:065" xml:lang="en">MDKSA-2003:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-181.html" xml:lang="en">RHSA-2003:181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-182.html" xml:lang="en">RHSA-2003:182</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0355">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror_embedded"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:1.0</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror_embedded</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0355</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:07.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320707" xml:lang="en">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</vuln:reference>
    </vuln:references>
    <vuln:summary>Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0356">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0356</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A69" name="oval:org.mitre.oval:def:69"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-313" xml:lang="en">DSA-313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00009.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/641013" xml:lang="en">VU#641013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067" xml:lang="en">MDKSA-2003:067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0357">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0357</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A73" name="oval:org.mitre.oval:def:73"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-313" xml:lang="en">DSA-313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00009.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/232164" xml:lang="en">VU#232164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/361700" xml:lang="en">VU#361700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067" xml:lang="en">MDKSA-2003:067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7494" xml:lang="en">7494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7495" xml:lang="en">7495</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0358">
    <vuln:cve-id>CVE-2003-0358</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://nethack.sourceforge.net/v340/bugmore/secpatch.txt" xml:lang="en">http://nethack.sourceforge.net/v340/bugmore/secpatch.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-316" xml:lang="en">DSA-316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-350" xml:lang="en">DSA-350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311172/2003-02-08/2003-02-14/0" xml:lang="en">20030209 #!ICadv-02.09.03: nethack 3.4.0 local buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6806" xml:lang="en">6806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11283" xml:lang="en">nethack-s-command-bo(11283)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0359">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stichting_mathematisch_centrum:nethack:3.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stichting_mathematisch_centrum:nethack:3.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0359</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:08.003-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-316" xml:lang="en">DSA-316</vuln:reference>
    </vuln:references>
    <vuln:summary>nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0360">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.1::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.2::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.3::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.4::woody_gps_package"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.1::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.2::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.3::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.4::woody_gps_package</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0360</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:08.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gps.seul.org/changelog.html" xml:lang="en">http://gps.seul.org/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-307" xml:lang="en">DSA-307</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0361">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.1::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.2::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.3::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.4::woody_gps_package"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.1::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.2::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.3::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.4::woody_gps_package</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0361</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:08.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gps.seul.org/changelog.html" xml:lang="en">http://gps.seul.org/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-307" xml:lang="en">DSA-307</vuln:reference>
    </vuln:references>
    <vuln:summary>gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0362">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.1::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.2::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.3::woody_gps_package"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.9.4::woody_gps_package"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.1::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.2::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.3::woody_gps_package</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.9.4::woody_gps_package</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0362</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:08.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gps.seul.org/changelog.html" xml:lang="en">http://gps.seul.org/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-307" xml:lang="en">DSA-307</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0363">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:licq:licq:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:licq:licq:1.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:licq:licq:1.0.3</vuln:product>
      <vuln:product>cpe:/a:licq:licq:1.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0363</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:08.660-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T18:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf" xml:lang="en">http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0364">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0364</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A295" name="oval:org.mitre.oval:def:295"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-187.html" xml:lang="en">RHSA-2003:187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-195.html" xml:lang="en">RHSA-2003:195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-41.txt" xml:lang="en">TLSA-2003-41</vuln:reference>
    </vuln:references>
    <vuln:summary>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0365">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:icq_inc:icqlite:2003a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:icq_inc:icqlite:2003a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0365</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:00.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105427404625027&amp;w=2" xml:lang="en">20030529 ICQLite executable trojaning</vuln:reference>
    </vuln:references>
    <vuln:summary>ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables with malicious programs.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0366">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lysator:lyskom-server:2.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lysator:lyskom-server:2.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0366</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:09.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-318" xml:lang="en">DSA-318</vuln:reference>
    </vuln:references>
    <vuln:summary>lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0367">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:gzip:1.3.5</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0367</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-05-23T10:04:52.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-05-23T08:45:11.260-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-308" xml:lang="en">DSA-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:068" xml:lang="en">MDKSA-2003:068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html" xml:lang="en">http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7872" xml:lang="en">7872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-38.txt" xml:lang="en">TLSA-2003-38</vuln:reference>
    </vuln:references>
    <vuln:summary>znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0368">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nokia:ggsn:release_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:ggsn:release_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0368</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a060903-1.txt" xml:lang="en">A060903-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/924812" xml:lang="en">VU#924812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7854" xml:lang="en">7854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12221" xml:lang="en">nokia-ggsn-ip-dos(12221)</vuln:reference>
    </vuln:references>
    <vuln:summary>Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0370">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror_embedded:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror_embedded:0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:7.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:8.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:7.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0370</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:47.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.html" xml:lang="en">20030510 [forward]Apple Safari and Konqueror Embedded Common Name Verification Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-361" xml:lang="en">DSA-361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20030602-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20030602-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-192.html" xml:lang="en">RHSA-2003:192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-193.html" xml:lang="en">RHSA-2003:193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320707" xml:lang="en">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7520" xml:lang="en">7520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-36.txt" xml:lang="en">TLSA-2003-36</vuln:reference>
    </vuln:references>
    <vuln:summary>Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0371">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:prishtina_soft:prishtina_ftp:v.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:prishtina_soft:prishtina_ftp:v.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0371</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:01.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105370592729044&amp;w=2" xml:lang="en">20030522 Prishtina FTP v.1.*: remote DoS</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0372">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nessus:nessus:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nessus:nessus:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0372</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:03.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105364059803427&amp;w=2" xml:lang="en">20030522 Potential security vulnerability in Nessus</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105369506714849&amp;w=2" xml:lang="en">20030523 nessus NASL scripting engine security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7664" xml:lang="en">7664</vuln:reference>
    </vuln:references>
    <vuln:summary>Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0373">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nessus:nessus:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nessus:nessus:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0373</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:04.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105364059803427&amp;w=2" xml:lang="en">20030522 Potential security vulnerability in Nessus</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105369506714849&amp;w=2" xml:lang="en">20030523 nessus NASL scripting engine security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7664" xml:lang="en">7664</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0374">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nessus:nessus:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nessus:nessus:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0374</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:05.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105364059803427&amp;w=2" xml:lang="en">20030522 Potential security vulnerability in Nessus</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7664" xml:lang="en">7664</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0375">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xmb_forum:xmb:1.6</vuln:product>
      <vuln:product>cpe:/a:xmb_forum:xmb:1.8</vuln:product>
      <vuln:product>cpe:/a:xmb_forum:xmb:1.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0375</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:07.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.xmbforum.com/viewthread.php?tid=773046" xml:lang="en">http://forums.xmbforum.com/viewthread.php?tid=773046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105363936402228&amp;w=2" xml:lang="en">20030522 XMB 1.8 Partagium cross site scripting vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7662" xml:lang="en">7662</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0376">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora:5.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:eudora:5.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0376</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:08.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105370625529452&amp;w=2" xml:lang="en">20030523 Eudora 5.2.1 buffer overflow DoS</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large number of . (dot) characters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0377">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:iisprotect:iisprotect:2.2_r4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:iisprotect:iisprotect:2.2_r4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0377</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:09.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105370528728225&amp;w=2" xml:lang="en">20030523 iisPROTECT SQL injection in admin interface</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0378">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0378</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:10.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=107579" xml:lang="en">http://docs.info.apple.com/article.html?artnum=107579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/467828" xml:lang="en">VU#467828</vuln:reference>
    </vuln:references>
    <vuln:summary>The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0379">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:afp_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:afp_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0379</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:32.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00030.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00030.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0380">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:atftpd:atftpd:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:atftpd:atftpd:0.6.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:atftpd:atftpd:0.6.0</vuln:product>
      <vuln:product>cpe:/a:atftpd:atftpd:0.6.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0380</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:11.113-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0056.html" xml:lang="en">20030606 atftpd bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-314" xml:lang="en">DSA-314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/82/323886/2003-06-02/2003-06-08/0" xml:lang="en">20030604 possible remote buffer overflow in atftpd</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0381">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:norman_ramsey:noweb:2.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:norman_ramsey:noweb:2.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0381</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:11.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-323" xml:lang="en">DSA-323</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0382">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.9.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0382</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:10.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105427580626001&amp;w=2" xml:lang="en">20030509 BAZARR CODE NINER PINK TEAM GO GO GO</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-309" xml:lang="en">DSA-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7708" xml:lang="en">7708</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0385">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0.18::potato"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0.23::woody"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:3.0.18::potato</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0.23::woody</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0385</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:11.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105491469815197&amp;w=2" xml:lang="en">20030605 BAZARR LOCAL ROOT AGAIN. HI GUYS. DONT READ THIS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-310" xml:lang="en">DSA-310</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0386">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0386</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9894" name="oval:org.mitre.oval:def:9894"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" xml:lang="en">20060703-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/978316" xml:lang="en">VU#978316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0298.html" xml:lang="en">RHSA-2006:0298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0698.html" xml:lang="en">RHSA-2006:0698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0" xml:lang="en">20030605 OpenSSH remote clent address restriction circumvention</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7831" xml:lang="en">7831</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html" xml:lang="en">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html" xml:lang="en">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0388">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:andrew_morgan:linux_pam:0.77"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:andrew_morgan:linux_pam:0.77</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0388</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:13.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105577915506761&amp;w=2" xml:lang="en">20030616 FW: iDEFENSE Security Advisory 06.16.03: Linux-PAM getlogin() Spoofing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/06.16.03.txt" xml:lang="en">http://www.idefense.com/advisory/06.16.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-304.html" xml:lang="en">RHSA-2004:304</vuln:reference>
    </vuln:references>
    <vuln:summary>pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0389">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rsa:ace_agent:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rsa:ace_agent:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0389</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:11.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0112.html" xml:lang="en">20030619 R7-0014: RSA SecurID ACE Agent Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0014.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0014.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0390">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:james_theiler:opt:3.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:james_theiler:opt:3.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0390</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:14.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105121918523320&amp;w=2" xml:lang="en">20030424 SRT2003-04-24-1532 -  Options Parsing Tool library buffer overflows.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105371246204866&amp;w=2" xml:lang="en">20030523 Re: Options Parsing Tool library buffer overflows.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz" xml:lang="en">http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0391">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:amax_information_technologies:magic_winmail_server:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:amax_information_technologies:magic_winmail_server:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0391</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:15.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105370528428222&amp;w=2" xml:lang="en">20030523 Magic Winmail Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.magicwinmail.net/changelog.asp" xml:lang="en">http://www.magicwinmail.net/changelog.asp</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0392">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:st:ftp_service:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:st:ftp_service:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0392</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:17.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105372353017778&amp;w=2" xml:lang="en">20030523 ST FTP Service v3.0: directory traversal</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive letter argument (e.g. E:).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0393">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:privacyware:privatefirewall:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:privacyware:privatefirewall:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0393</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:18.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105380229532320&amp;w=2" xml:lang="en">20030524 Some problems in Privatefirewall 3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7700" xml:lang="en">7700</vuln:reference>
    </vuln:references>
    <vuln:summary>Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services via FIN scans or Xmas scans.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0394">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:blnews:blnews:2.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:blnews:blnews:2.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0394</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:19.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105379530927567&amp;w=2" xml:lang="en">20030524 PHP source code injection in BLNews</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7677" xml:lang="en">7677</vuln:reference>
    </vuln:references>
    <vuln:summary>objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0395">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php_outburst:ultimate_php_board_upb:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_outburst:ultimate_php_board_upb:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0395</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:21.310-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://f0kp.iplus.ru/bz/024.en.txt" xml:lang="en">http://f0kp.iplus.ru/bz/024.en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105379741528925&amp;w=2" xml:lang="en">20030524 UPB: Discussion Board/Web-Site Takeover</vuln:reference>
    </vuln:references>
    <vuln:summary>Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0396">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:linux-atm:linux-atm:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:linux-atm:linux-atm:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0396</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:31.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105154433926396&amp;w=2" xml:lang="en">20030428 ATM  on Linux Exploit Code Release (les, local)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405560021979&amp;w=2" xml:lang="en">20030524 ATM on linux Exploit(les,local)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=156242" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=156242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/5EP0M1P9PO.html" xml:lang="en">http://www.securiteam.com/exploits/5EP0M1P9PO.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7437" xml:lang="en">7437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11903" xml:lang="en">atmonlinux-les-command-bo(11903)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0397">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sharman_networks:kazaa:v2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sharman_networks:kazaa:v2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0397</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:23.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405708923565&amp;w=2" xml:lang="en">20030526 The PACKET 0' DEATH FastTrack network vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12086.php" xml:lang="en">fastrack-packet-0-bo(12086)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7680" xml:lang="en">7680</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0398">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0398</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:25.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405734223874&amp;w=2" xml:lang="en">20030526 S21SEC-016 - Vignette SSI Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12077.php" xml:lang="en">vignette-ssi-command-execution(12077)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-016-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-016-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7685" xml:lang="en">7685</vuln:reference>
    </vuln:references>
    <vuln:summary>Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0399">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0399</vuln:cve-id>
    <vuln:published-datetime>2003-07-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:26.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405874325673&amp;w=2" xml:lang="en">20030526 S21SEC-017 - Vignette /vgn/legacy/save SQL access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12076.php" xml:lang="en">vignette-save-obtain-information(12076)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-017-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-017-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7683" xml:lang="en">7683</vuln:reference>
    </vuln:references>
    <vuln:summary>Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0400">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.2</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0400</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:27.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405985126857&amp;w=2" xml:lang="en">20030526 S21SEC-018 - Vignette memory leak AIX Platform</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12075.php" xml:lang="en">vignette-memory-leak(12075)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-018-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-018-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7684" xml:lang="en">7684</vuln:reference>
    </vuln:references>
    <vuln:summary>Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0401">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0401</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:28.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405793324661&amp;w=2" xml:lang="en">20030526 S21SEC-019 - Vignette /vgn/style internal information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12074.php" xml:lang="en">vignette-style-info-disclosure(12074)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-019-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-019-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7688" xml:lang="en">7688</vuln:reference>
    </vuln:references>
    <vuln:summary>Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0402">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0402</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:30.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405880325755&amp;w=2" xml:lang="en">20030526 S21SEC-020 - Vignette user enumeration</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12073.php" xml:lang="en">vignette-login-account-bruteforce(12073)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/en/avisos/s21sec-020-en.txt" xml:lang="en">http://www.s21sec.com/en/avisos/s21sec-020-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7691" xml:lang="en">7691</vuln:reference>
    </vuln:references>
    <vuln:summary>The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0403">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0403</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:31.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405789924612&amp;w=2" xml:lang="en">20030526 S21SEC-021 - Vignette License access and modification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12072.php" xml:lang="en">vignette-license-modification(12072)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-021-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-021-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7694" xml:lang="en">7694</vuln:reference>
    </vuln:references>
    <vuln:summary>Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0404">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.0</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:4.1</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0404</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:32.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105406028027360&amp;w=2" xml:lang="en">20030526 S21SEC-023 -  Vignette multiple Cross Site Scripting vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12071.php" xml:lang="en">vignette-multiple-xss(12071)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-023-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-023-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7687" xml:lang="en">7687</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0405">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:content_suite:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:storyserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vignette:vignette:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vignette:content_suite:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0.1</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0.2</vuln:product>
      <vuln:product>cpe:/a:vignette:content_suite:6.0.3</vuln:product>
      <vuln:product>cpe:/a:vignette:storyserver:5.0</vuln:product>
      <vuln:product>cpe:/a:vignette:vignette:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0405</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:33.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405922826197&amp;w=2" xml:lang="en">20030526 S21SEC-024 - Vignette TCL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12070.php" xml:lang="en">vignette-tcl-code-execution(12070)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/es/avisos/s21sec-024-en.txt" xml:lang="en">http://www.s21sec.com/es/avisos/s21sec-024-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7690" xml:lang="en">7690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7692" xml:lang="en">7692</vuln:reference>
    </vuln:references>
    <vuln:summary>Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0406">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:palmvnc:palmvnc:1.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:palmvnc:palmvnc:1.40</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0406</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:34.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405691423389&amp;w=2" xml:lang="en">20030526 PalmVNC 1.40 Insecure Records</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12083.php" xml:lang="en">palmvnc-plaintext-passwords(12083)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7696" xml:lang="en">7696</vuln:reference>
    </vuln:references>
    <vuln:summary>PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0407">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:batalla_naval:1.0_4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:batalla_naval:1.0_4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0407</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:36.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405668423102&amp;w=2" xml:lang="en">20030526 [Priv8security_Advisory]_Batalla_Naval_remote_overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12087.php" xml:lang="en">batalla-naval-bo(12087)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7699" xml:lang="en">7699</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0408">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:the_uptimes_project:upclient:5.0b7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:the_uptimes_project:upclient:5.0b7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0408</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:37.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405629622652&amp;w=2" xml:lang="en">20030527 NuxAcid#002 - Buffer Overflow in UpClient</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12131.php" xml:lang="en">upclient-command-line-bo(12131)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7703" xml:lang="en">7703</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0409">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brs:webweaver:1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0409</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:38.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105405836025160&amp;w=2" xml:lang="en">20030527 BRS WebWeaver: POST and HEAD Overflaws</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12107.php" xml:lang="en">webweaver-head-post-bo(12107)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7695" xml:lang="en">7695</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0410">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:analogx:proxy:4.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:analogx:proxy:4.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0410</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:40.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0082.html" xml:lang="en">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105406759403978&amp;w=2" xml:lang="en">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.analogx.com/contents/download/network/proxy.htm" xml:lang="en">http://www.analogx.com/contents/download/network/proxy.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12068.php" xml:lang="en">analogx-proxy-url-bo(12068)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7681" xml:lang="en">7681</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0411">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:one_application_server:7.0::platform"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_application_server:7.0::standard"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:one_application_server:7.0::platform</vuln:product>
      <vuln:product>cpe:/a:sun:one_application_server:7.0::standard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0411</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:41.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2" xml:lang="en">20030526 Multiple Vulnerabilities in Sun-One Application Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" xml:lang="en">55221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" xml:lang="en">1000610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-103.shtml" xml:lang="en">N-103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12093.php" xml:lang="en">sunone-jsp-source-disclosure(12093)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7709" xml:lang="en">7709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.spidynamics.com/sunone_alert.html" xml:lang="en">http://www.spidynamics.com/sunone_alert.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0412">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:one_application_server:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:one_application_server:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0412</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:42.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2" xml:lang="en">20030526 Multiple Vulnerabilities in Sun-One Application Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" xml:lang="en">55221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" xml:lang="en">1000610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-103.shtml" xml:lang="en">N-103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7711" xml:lang="en">7711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.spidynamics.com/sunone_alert.html" xml:lang="en">http://www.spidynamics.com/sunone_alert.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0413">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:one_application_server:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:one_application_server:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0413</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:44.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2" xml:lang="en">20030526 Multiple Vulnerabilities in Sun-One Application Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" xml:lang="en">55221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57605" xml:lang="en">57605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201009-1" xml:lang="en">201009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" xml:lang="en">1000610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-103.shtml" xml:lang="en">N-103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12095.php" xml:lang="en">sunone-http-error-xss(12095)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7710" xml:lang="en">7710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.spidynamics.com/sunone_alert.html" xml:lang="en">http://www.spidynamics.com/sunone_alert.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0414">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:one_application_server:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:one_application_server:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0414</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:45.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2" xml:lang="en">20030526 Multiple Vulnerabilities in Sun-One Application Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" xml:lang="en">55221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" xml:lang="en">1000610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-103.shtml" xml:lang="en">N-103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12096.php" xml:lang="en">sunone-insecure-file-permissions(12096)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7712" xml:lang="en">7712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.spidynamics.com/sunone_alert.html" xml:lang="en">http://www.spidynamics.com/sunone_alert.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0415">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:access-remote-pc.com:remote_pc_access:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:access-remote-pc.com:remote_pc_access:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0415</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:46.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105417988811698&amp;w=2" xml:lang="en">20030528 Remote PC Access Server  2.2 Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7698" xml:lang="en">7698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ytech.co.il/advisories/rpca/rpcaccess.htm" xml:lang="en">http://www.ytech.co.il/advisories/rpca/rpcaccess.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0416">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bandmin:bandmin:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bandmin:bandmin:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0416</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:47.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105418152212771&amp;w=2" xml:lang="en">20030528 Bandmin 1.4 XSS Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12108.php" xml:lang="en">bandmin-index-xss(12108)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7729" xml:lang="en">7729</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0417">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:super-m:son_hserver:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:super-m:son_hserver:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0417</vuln:cve-id>
    <vuln:published-datetime>2003-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:49.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105417983711685&amp;w=2" xml:lang="en">20030529 Son hServer v0.2: directory traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12103.php" xml:lang="en">sonhserver-pipe-directory-traversal(12103)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7717" xml:lang="en">7717</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0418">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.39"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.39</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0418</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:50.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105519179005065&amp;w=2" xml:lang="en">20030609 Linux 2.0 remote info leak from too big icmp citation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt" xml:lang="en">http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/471084" xml:lang="en">VU#471084</vuln:reference>
    </vuln:references>
    <vuln:summary>The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0419">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:smc_networks:barricade_wireless_cable_dsl_broadband_router:smc7004vwbr"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:smc_networks:barricade_wireless_cable_dsl_broadband_router:smc7004vwbr</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0419</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:16.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/06.11.03.txt" xml:lang="en">http://www.idefense.com/advisory/06.11.03.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0420">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0420</vuln:cve-id>
    <vuln:published-datetime>2003-06-13T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3165" xml:lang="en">ESB-2003.0415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/JPLA-5NTL8E" xml:lang="en">http://www.kb.cert.org/vuls/id/JPLA-5NTL8E</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7894" xml:lang="en">7894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12342" xml:lang="en">macos-dsimportexport-obtain-information(12342)</vuln:reference>
    </vuln:references>
    <vuln:summary>Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0421">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0421</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:16.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0422">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0422</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:59.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0423">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0423</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:59.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0424">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0424</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:59.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0425">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0425</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:59.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0426">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0426</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:17.503-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0427">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:miod_vallat:mikmod:3.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miod_vallat:mikmod:3.1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0427</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10194" name="oval:org.mitre.oval:def:10194"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A647" name="oval:org.mitre.oval:def:647"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-320" xml:lang="en">DSA-320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-506.html" xml:lang="en">RHSA-2005:506</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0428">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0428</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A75" name="oval:org.mitre.oval:def:75"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" xml:lang="en">CSSA-2003-030.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" xml:lang="en">CLA-2003:662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-324" xml:lang="en">DSA-324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00010.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/542540" xml:lang="en">VU#542540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0429">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0429</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A84" name="oval:org.mitre.oval:def:84"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" xml:lang="en">CSSA-2003-030.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" xml:lang="en">CLA-2003:662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-324" xml:lang="en">DSA-324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00010.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:summary>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0430">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0430</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A88" name="oval:org.mitre.oval:def:88"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" xml:lang="en">CSSA-2003-030.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" xml:lang="en">CLA-2003:662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00010.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:summary>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0431">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0431</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:09.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A101" name="oval:org.mitre.oval:def:101"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" xml:lang="en">CSSA-2003-030.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" xml:lang="en">CLA-2003:662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-324" xml:lang="en">DSA-324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00010.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:summary>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0432">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0432</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A106" name="oval:org.mitre.oval:def:106"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" xml:lang="en">CSSA-2003-030.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" xml:lang="en">CLA-2003:662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-324" xml:lang="en">DSA-324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00010.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:summary>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0433">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnocatan-develop:gnocatan:0.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnocatan-develop:gnocatan:0.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0433</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:18.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-315" xml:lang="en">DSA-315</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in gnocatan 0.6.1 and earlier allow attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0434">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:5.0.6</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0434</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A664" name="oval:org.mitre.oval:def:664"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.html" xml:lang="en">20030613 -10Day CERT Advisory on PDF Files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105777963019186&amp;w=2" xml:lang="en">20030709 xpdf vulnerability - CAN-2003-0434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/200132" xml:lang="en">VU#200132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:071" xml:lang="en">MDKSA-2003:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-196.html" xml:lang="en">RHSA-2003:196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-197.html" xml:lang="en">RHSA-2003:197</vuln:reference>
    </vuln:references>
    <vuln:summary>Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0435">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:typespeed:typespeed:0.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:typespeed:typespeed:0.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0435</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:53.223-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105553002105111&amp;w=2" xml:lang="en">20030612 BAZARR THUG LIFE , DONT READ OR VIRUS INFECT YOU</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-322" xml:lang="en">DSA-322</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0436">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mnogosearch:mnogosearch:3.1.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mnogosearch:mnogosearch:3.1.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0436</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:00.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html" xml:lang="en">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7865" xml:lang="en">7865</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0437">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mnogosearch:mnogosearch:3.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mnogosearch:mnogosearch:3.2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0437</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:00.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html" xml:lang="en">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7866" xml:lang="en">7866</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0438">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yuuichi_teranishi:eldav:0.7.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yuuichi_teranishi:eldav:0.7.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0438</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:19.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-325" xml:lang="en">DSA-325</vuln:reference>
    </vuln:references>
    <vuln:summary>eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0439">
    <vuln:cve-id>CVE-2003-0439</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.837-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.837-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0440">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:semi:semi:1.14.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:semi:semi:1.14.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0440</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A569" name="oval:org.mitre.oval:def:569"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-339" xml:lang="en">DSA-339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-231.html" xml:lang="en">RHSA-2003:231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-234.html" xml:lang="en">RHSA-2003:234</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0441">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:orville-write:orville-write:2.53"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:orville-write:orville-write:2.53</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0441</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-326" xml:lang="en">DSA-326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7988" xml:lang="en">7988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12381" xml:lang="en">orvillewrite-variables-bo(12381)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0442">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0442</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A485" name="oval:org.mitre.oval:def:485"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" xml:lang="en">CLSA-2003:691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105449314612963&amp;w=2" xml:lang="en">20030530 PHP Trans SID  XSS (Was: New php release with security fixes)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105760591228031&amp;w=2" xml:lang="en">20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://shh.thathost.com/secadv/2003-05-11-php.txt" xml:lang="en">http://shh.thathost.com/secadv/2003-05-11-php.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-112.shtml" xml:lang="en">N-112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-351" xml:lang="en">DSA-351</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:082" xml:lang="en">MDKSA-2003:082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-204.html" xml:lang="en">RHSA-2003:204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7761" xml:lang="en">7761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008653" xml:lang="en">1008653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.co.jp/security/2003/TLSA-2003-47j.txt" xml:lang="en">TLSA-2003-47</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12259" xml:lang="en">php-session-id-xss(12259)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0444">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gtksee:gtksee:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gtksee:gtksee:0.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gtksee:gtksee:0.5</vuln:product>
      <vuln:product>cpe:/a:gtksee:gtksee:0.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0444</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-337" xml:lang="en">DSA-337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8061" xml:lang="en">8061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12462" xml:lang="en">gtksee-png-bo(12462)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0445">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webfs:webfs:1.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0445</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:19.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-328" xml:lang="en">DSA-328</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0446">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0446</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0120.html" xml:lang="en">20030617 Re: Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005762.html" xml:lang="en">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105585986015421&amp;w=2" xml:lang="en">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105595990924165&amp;w=2" xml:lang="en">20030617 Re: [Full-Disclosure] Cross-Site Scripting in Unparsable XML Files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105585001905002&amp;w=2" xml:lang="en">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.greymagic.com/adv/gm013-ie/" xml:lang="en">http://security.greymagic.com/adv/gm013-ie/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7938" xml:lang="en">7938</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12334" xml:lang="en">ie-msxml-xss(12334)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0447">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0447</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:57.003-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html" xml:lang="en">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105585933614773&amp;w=2" xml:lang="en">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105585142406147&amp;w=2" xml:lang="en">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.greymagic.com/adv/gm014-ie/" xml:lang="en">http://security.greymagic.com/adv/gm014-ie/</vuln:reference>
    </vuln:references>
    <vuln:summary>The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0448">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aboleo.net:portmon:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aboleo.net:portmon:1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0448</vuln:cve-id>
    <vuln:published-datetime>2003-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:58.160-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105588111714856&amp;w=2" xml:lang="en">20030618 Portmon file arbitrary read/write access vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0449">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:progress:database:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:progress:database:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0449</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:33:59.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105561134624665&amp;w=2" xml:lang="en">20030614 SRT2003-06-13-0945 - Progress PATH based dlopen() issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105561189625082&amp;w=2" xml:lang="en">20030614 SRT2003-06-13-1009 - Progress _dbagent -installdir dlopen() issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0450">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cistron:radius_daemon:1.6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cistron:radius_daemon:1.6.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0450</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:02.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000664" xml:lang="en">CLA-2003:664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-321" xml:lang="en">DSA-321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_030_radiusd_cistron.html" xml:lang="en">SuSE-SA:2003:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-40.txt" xml:lang="en">TLSA-2003-40</vuln:reference>
    </vuln:references>
    <vuln:summary>Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0451">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xblockout:xbl:1.0j"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xblockout:xbl:1.0j</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0451</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:20.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-327" xml:lang="en">DSA-327</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0452">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gunnar_ritter:osh:1.7-10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gunnar_ritter:osh:1.7-10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0452</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:20.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-329" xml:lang="en">DSA-329</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0453">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ehud_gavron:traceroute-nanog:6.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ehud_gavron:traceroute-nanog:6.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0453</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:00.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105613905425563&amp;w=2" xml:lang="en">20030620 BAZARR FAREWELL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-348" xml:lang="en">DSA-348</vuln:reference>
    </vuln:references>
    <vuln:summary>traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0454">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:joe_rumsey:xgalaga:2.0.34"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joe_rumsey:xgalaga:2.0.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0454</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:21.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-334" xml:lang="en">DSA-334</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0455">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:libmagick_library:5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:imagemagick:libmagick_library:5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0455</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:01.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105786393628728&amp;w=2" xml:lang="en">20030710 [OpenPKG-SA-2003.034] OpenPKG Security Advisory (imagemagick)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-331" xml:lang="en">DSA-331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-494.html" xml:lang="en">RHSA-2004:494</vuln:reference>
    </vuln:references>
    <vuln:summary>The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0456">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:deerfield:visnetic_website:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:deerfield:visnetic_website:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:deerfield:visnetic_website:3.5.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:deerfield:visnetic_website:3.5.13</vuln:product>
      <vuln:product>cpe:/a:deerfield:visnetic_website:3.5.15</vuln:product>
      <vuln:product>cpe:/a:deerfield:visnetic_website:3.5.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0456</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0002.html" xml:lang="en">20030701 VisNetic WebSite Path Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105733894003737&amp;w=2" xml:lang="en">20030701 VisNetic WebSite Path Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.krusesecurity.dk/advisories/vis0103.txt" xml:lang="en">http://www.krusesecurity.dk/advisories/vis0103.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8075" xml:lang="en">8075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12483" xml:lang="en">visnetic-website-path-disclosure(12483)</vuln:reference>
    </vuln:references>
    <vuln:summary>VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0458">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d40.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d41.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d42.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d42.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d43.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d43.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d43.02"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d44.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d44.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d44.02"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d45.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d45.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d46.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d47.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d48.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d48.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d48.02"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:d48.03"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g01.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g02.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g03.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g04.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g05.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g05.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.03"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.04"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.10"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.11"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.12"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.13"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.14"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.15"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.16"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.17"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.18"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.19"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:nonstop_seeview_server_gateway:g06.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d40.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d41.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d42.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d42.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d43.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d43.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d43.02</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d44.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d44.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d44.02</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d45.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d45.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d46.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d47.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d48.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d48.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d48.02</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:d48.03</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g01.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g02.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g03.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g04.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g05.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g05.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.00</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.01</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.03</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.04</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.05</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.06</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.07</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.08</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.09</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.10</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.11</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.12</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.13</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.14</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.15</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.16</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.17</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.18</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.19</vuln:product>
      <vuln:product>cpe:/a:hp:nonstop_seeview_server_gateway:g06.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0458</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:21.690-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5545" xml:lang="en">SSRT3488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8080" xml:lang="en">8080</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0459">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror_embedded:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:analog_real-time_synthesizer:2.1.1-5::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:analog_real-time_synthesizer:2.2-11::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:analog_real-time_synthesizer:2.2-11::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:3.0.3-13::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:3.0.3-13::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs:2.1.1-5::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs:2.2-11::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs:2.2-11::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs:3.0.0-10::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs:3.1-10::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_devel:2.1.1-5::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_devel:2.2-11::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_devel:2.2-11::ia64_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_devel:3.0.0-10::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_devel:3.0.3-8::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_devel:3.1-10::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_sound:2.1.1-5::i386_sound"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_sound:2.2-11::i386_sound"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_sound:2.2-11::ia64_sound"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_sound_devel:2.1.1-5::i386_sound_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_sound_devel:2.2-11::i386_sound_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdelibs_sound_devel:2.2-11::ia64_sound_dev"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:konqueror:2.1.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:2.2.2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.3</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.5</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.1.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.1.2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror_embedded:0.1</vuln:product>
      <vuln:product>cpe:/a:redhat:analog_real-time_synthesizer:2.1.1-5::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:analog_real-time_synthesizer:2.2-11::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:analog_real-time_synthesizer:2.2-11::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:3.0.3-13::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:3.0.3-13::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs:2.1.1-5::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs:2.2-11::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs:2.2-11::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs:3.0.0-10::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs:3.1-10::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_devel:2.1.1-5::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_devel:2.2-11::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_devel:2.2-11::ia64_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_devel:3.0.0-10::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_devel:3.0.3-8::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_devel:3.1-10::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_sound:2.1.1-5::i386_sound</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_sound:2.2-11::i386_sound</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_sound:2.2-11::ia64_sound</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_sound_devel:2.1.1-5::i386_sound_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_sound_devel:2.2-11::i386_sound_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:kdelibs_sound_devel:2.2-11::ia64_sound_dev</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0459</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A411" name="oval:org.mitre.oval:def:411"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" xml:lang="en">CLA-2003:747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007300.html" xml:lang="en">20030729 KDE Security Advisory: Konqueror Referrer Authentication Leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105986238428061&amp;w=2" xml:lang="en">20030802 [slackware-security]  KDE packages updated (SSA:2003-213-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-361" xml:lang="en">DSA-361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20030729-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20030729-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:079" xml:lang="en">MDKSA-2003:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-235.html" xml:lang="en">RHSA-2003:235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-236.html" xml:lang="en">RHSA-2003:236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-45.txt" xml:lang="en">TLSA-2003-45</vuln:reference>
    </vuln:references>
    <vuln:summary>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0460">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0460</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:22.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/httpd/Announcement.html" xml:lang="en">http://www.apache.org/dist/httpd/Announcement.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/694428" xml:lang="en">VU#694428</vuln:reference>
    </vuln:references>
    <vuln:summary>The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0461">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0461</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A304" name="oval:org.mitre.oval:def:304"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9330" name="oval:org.mitre.oval:def:9330"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A997" name="oval:org.mitre.oval:def:997"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html" xml:lang="en">http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-188.html" xml:lang="en">RHSA-2004:188</vuln:reference>
    </vuln:references>
    <vuln:summary>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0462">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:8.2"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:8.2::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:8.2</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:8.2::ppc</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0462</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A309" name="oval:org.mitre.oval:def:309"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0463">
    <vuln:cve-id>CVE-2003-0463</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:05.273-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0464">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0464</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A311" name="oval:org.mitre.oval:def:311"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:summary>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0465">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0465</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10285" name="oval:org.mitre.oval:def:10285"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=linux-kernel&amp;m=105796021120436&amp;w=2" xml:lang="en">http://marc.info/?l=linux-kernel&amp;m=105796021120436&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=linux-kernel&amp;m=105796415223490&amp;w=2" xml:lang="en">http://marc.info/?l=linux-kernel&amp;m=105796415223490&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-188.html" xml:lang="en">RHSA-2004:188</vuln:reference>
    </vuln:references>
    <vuln:summary>The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as opposed to the expected behavior of strncpy as implemented in libc, which could lead to information leaks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0466">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:wu_ftpd:2.6.1-16::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:wu_ftpd:2.6.1-16::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:wu_ftpd:2.6.1-18::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:wu_ftpd:2.6.1-18::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:wu_ftpd:2.6.2-5::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:wu_ftpd:2.6.2-8::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:wu_ftpd:2.6.1-16::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:wu_ftpd:2.6.1-16::powerpc</vuln:product>
      <vuln:product>cpe:/a:redhat:wu_ftpd:2.6.1-18::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:wu_ftpd:2.6.1-18::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:wu_ftpd:2.6.2-5::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:wu_ftpd:2.6.2-8::i386</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.5.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:alpha</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0466</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.520-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1970" name="oval:org.mitre.oval:def:1970"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-011.txt.asc" xml:lang="en">NetBSD-SA2003-011.txt.asc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0065.html" xml:lang="en">20030731 wu-ftpd fb_realpath() off-by-one bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-019-01" xml:lang="en">IMNX-2003-7+-019-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105967301604815&amp;w=2" xml:lang="en">20030731 wu-ftpd fb_realpath() off-by-one bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106001410028809&amp;w=2" xml:lang="en">FreeBSD-SA-03:08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106001702232325&amp;w=2" xml:lang="en">20030804 wu-ftpd-2.6.2 off-by-one remote exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106002488209129&amp;w=2" xml:lang="en">20030804 Off-by-one Buffer Overflow Vulnerability in BSD libc realpath(3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007380" xml:lang="en">1007380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001257.1-1" xml:lang="en">1001257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-357" xml:lang="en">DSA-357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/743092" xml:lang="en">VU#743092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:080" xml:lang="en">MDKSA-2003:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_032_wuftpd.html" xml:lang="en">SuSE-SA:2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-245.html" xml:lang="en">RHSA-2003:245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-246.html" xml:lang="en">RHSA-2003:246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/424852/100/0/threaded" xml:lang="en">20060213 Latest wu-ftpd exploit :-s</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/425061/100/0/threaded" xml:lang="en">20060214 Re: Latest wu-ftpd exploit :-s</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8315" xml:lang="en">8315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-46.txt" xml:lang="en">TLSA-2003-46</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12785" xml:lang="en">libc-realpath-offbyone-bo(12785)</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0467">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0467</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:08.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105985703724758&amp;w=2" xml:lang="en">20030802 [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0468">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1999-09-06"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1999-12-31"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:2000-02-28"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:2001-11-15"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wietse_venema:postfix:1.0.21</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1.1.11</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1999-09-06</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1999-12-31</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:2000-02-28</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:2001-11-15</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:7.0</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0468</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522" name="oval:org.mitre.oval:def:522"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717" xml:lang="en">CLA-2003:717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106001525130257&amp;w=2" xml:lang="en">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-363" xml:lang="en">DSA-363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081" xml:lang="en">MDKSA-2003:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_033_postfix.html" xml:lang="en">SuSE-SA:2003:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-251.html" xml:lang="en">RHSA-2003:251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8333" xml:lang="en">8333</vuln:reference>
    </vuln:references>
    <vuln:summary>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0469">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0469</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:45.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006155.html" xml:lang="en">20030701 PoC for Internet Explorer >=5.0 buffer overflow (trivial exploit for hard case).</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006067.html" xml:lang="en">20030625 Re: Internet Explorer >=5.0 : Buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105639925122961&amp;w=2" xml:lang="en">20030622 Internet Explorer >=5.0 : Buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-14.html" xml:lang="en">CA-2003-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/823260" xml:lang="en">VU#823260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8016" xml:lang="en">8016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-023" xml:lang="en">MS03-023</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0470">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:security_check"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:security_check</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0470</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html" xml:lang="en">20030622 Symantec ActiveX control buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105647537823877&amp;w=2" xml:lang="en">20030624 [Symantec Security Advisor] Symantec Security Check ActiveX Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007029" xml:lang="en">1007029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/527228" xml:lang="en">VU#527228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8008" xml:lang="en">8008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12423" xml:lang="en">symantec-security-activex-bo(12423)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0471">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alt-n:webadmin</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0471</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:13.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105647081418155&amp;w=2" xml:lang="en">20030624 Remote Buffer Overrun WebAdmin.exe</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105648385900792&amp;w=2" xml:lang="en">20030624 Re: WebAdmin from ALT-N remote exploit PoC</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8024" xml:lang="en">8024</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0472">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0472</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" xml:lang="en">20030607-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8027" xml:lang="en">8027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12676" xml:lang="en">irix-inetd-portscan-dos(12676)</vuln:reference>
    </vuln:references>
    <vuln:summary>The IPv6 capability in IRIX 6.5.19 allows remote attackers to cause a denial of service (hang) in inetd via port scanning.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0473">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0473</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" xml:lang="en">20030607-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8029" xml:lang="en">8029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12677" xml:lang="en">irix-snoop-gain-privileges(12677)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0474">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ashley_brown:iweb_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ashley_brown:iweb_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0474</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:14.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105049794801319&amp;w=2" xml:lang="en">20030416 SFAD03-001: iWeb Mini Web Server Remote Directory Traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105673543626636&amp;w=2" xml:lang="en">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0475">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ashley_brown:iweb_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ashley_brown:iweb_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0475</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:16.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105640001823769&amp;w=2" xml:lang="en">20030623 TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105673543626636&amp;w=2" xml:lang="en">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0476">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0476</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A327" name="oval:org.mitre.oval:def:327"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105664924024009&amp;w=2" xml:lang="en">20030626 Linux 2.4.x execve() file read race vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" xml:lang="en">MDKSA-2003:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-368.html" xml:lang="en">RHSA-2003:368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-408.html" xml:lang="en">RHSA-2003:408</vuln:reference>
    </vuln:references>
    <vuln:summary>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0477">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wzdftpd:wzdftpd:0.1_rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wzdftpd:wzdftpd:0.1_rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0477</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:18.553-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105674242105302&amp;w=2" xml:lang="en">20030627 wzdftpd remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.wzdftpd.net/changea.html" xml:lang="en">http://www.wzdftpd.net/changea.html</vuln:reference>
    </vuln:references>
    <vuln:summary>wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0478">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andromede:adromedeircd:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:daniel_moss:methane:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hans_westerhof:digatech:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wenet:ircd-ru"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:bahamut:ircd:1.4.35"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andromede:adromedeircd:1.2.3</vuln:product>
      <vuln:product>cpe:/a:daniel_moss:methane:0.1.1</vuln:product>
      <vuln:product>cpe:/a:hans_westerhof:digatech:1.2.1</vuln:product>
      <vuln:product>cpe:/a:wenet:ircd-ru</vuln:product>
      <vuln:product>cpe:/o:bahamut:ircd:1.4.35</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0478</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:19.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105665996104723&amp;w=2" xml:lang="en">20030626 Bahamut IRCd &lt;= 1.4.35 and several derived daemons</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105673489525906&amp;w=2" xml:lang="en">20030627 Re: Bahamut IRCd &lt;= 1.4.35 and several derived daemons</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105673555726823&amp;w=2" xml:lang="en">20030627 Bahamut DoS</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0479">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0479</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:20.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105673452325230&amp;w=2" xml:lang="en">20030627 WebBBS Guestbook : Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0480">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0480</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:22.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105673688529147&amp;w=2" xml:lang="en">20030627 VMware Workstation 4.0: Possible privilege escalation on the host</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019" xml:lang="en">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0481">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gero_kohnert:tutos:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gero_kohnert:tutos:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0481</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:23.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105638743109781&amp;w=2" xml:lang="en">20030623 [KSA-001] Multiple vulnerabilities in Tutos</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0482">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gero_kohnert:tutos:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gero_kohnert:tutos:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0482</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:24.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105638743109781&amp;w=2" xml:lang="en">20030623 [KSA-001] Multiple vulnerabilities in Tutos</vuln:reference>
    </vuln:references>
    <vuln:summary>TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0483">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xmb_forum:xmb:1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0483</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:26.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105638720409307&amp;w=2" xml:lang="en">20030623 Many XSS Vulnerabilities in XMB Forum.</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0484">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0484</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:27.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105639883722514&amp;w=2" xml:lang="en">20030621 XSS Exploit In phpBB viewtopic.php</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0485">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:progress:4gl_compiler:9.1:d06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:progress:4gl_compiler:9.1:d06</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0485</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:28.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105613243117155&amp;w=2" xml:lang="en">20030620 SRT2003-06-20-1232 - Progress 4GL Compiler datatype overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7997" xml:lang="en">7997</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0486">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0486</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105607263130644&amp;w=2" xml:lang="en">20030619 phpBB password disclosure by sql injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpbb.com/phpBB/viewtopic.php?t=112052" xml:lang="en">http://www.phpbb.com/phpBB/viewtopic.php?t=112052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7979" xml:lang="en">7979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12366" xml:lang="en">phpbb-viewtopic-sql-injection(12366)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0487">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kerio:kerio_mailserver:5.6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:kerio_mailserver:5.6.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0487</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105596982503760&amp;w=2" xml:lang="en">20030618 Multiple buffer overflows and XSS in Kerio MailServer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" xml:lang="en">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7967" xml:lang="en">7967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12368" xml:lang="en">kerio-multiple-modules-bo(12368)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0488">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kerio:kerio_mailserver:5.6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:kerio_mailserver:5.6.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0488</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105596982503760&amp;w=2" xml:lang="en">20030618 Multiple buffer overflows and XSS in Kerio MailServer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" xml:lang="en">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7966" xml:lang="en">7966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7968" xml:lang="en">7968</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12367" xml:lang="en">kerio-multiple-modules-xss(12367)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0489">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_c._toren:tcptraceroute:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_c._toren:tcptraceroute:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0489</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:26.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-330" xml:lang="en">DSA-330</vuln:reference>
    </vuln:references>
    <vuln:summary>tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0490">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dantz:retrospect_client:5.0.540"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dantz:retrospect_client:5.0.540</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0490</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:33.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105579526026992&amp;w=2" xml:lang="en">20030616 Dantz Retrospect Client 5.0.540 for Mac OS X - permission issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0491">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mytutorials:tutorials:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mytutorials:tutorials:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0491</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:34.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=vuln-dev&amp;m=105577873506147&amp;w=2" xml:lang="en">20030616 Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials"</vuln:reference>
    </vuln:references>
    <vuln:summary>The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0492">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0492</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105578322012128&amp;w=2" xml:lang="en">20030616 Multiple Vulnerabilities In Snitz Forums</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7922" xml:lang="en">7922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12325" xml:lang="en">snitz-search-xss(12325)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0493">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0493</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:37.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105578322012128&amp;w=2" xml:lang="en">20030616 Multiple Vulnerabilities In Snitz Forums</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7924" xml:lang="en">7924</vuln:reference>
    </vuln:references>
    <vuln:summary>Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0494">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0494</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:32.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105578322012128&amp;w=2" xml:lang="en">20030616 Multiple Vulnerabilities In Snitz Forums</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7925" xml:lang="en">7925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12326" xml:lang="en">snitz-forums-password-reset(12326)</vuln:reference>
    </vuln:references>
    <vuln:summary>password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0495">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ledscripts.com:lednews:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ledscripts.com:lednews:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0495</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105578330812212&amp;w=2" xml:lang="en">20030615 XSS Vulnerability in LedNews (CGI/Perl) v0.7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7920" xml:lang="en">7920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12304" xml:lang="en">lednews-message-xss(12304)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0496">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0496</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html" xml:lang="en">20030709 Pipe Filename Local Privilege Escalation FAQ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105820282607865&amp;w=2" xml:lang="en">20030714 @stake named pipe exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105830986720243&amp;w=2" xml:lang="en">20030715 CreateFile exploit, (working)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a070803-1.txt" xml:lang="en">A070803-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0497">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0497</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-10T07:17:40.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=7" xml:lang="en">20030701 Caché Insecure Installation File and Directory Permissions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/" xml:lang="en">https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/</vuln:reference>
    </vuln:references>
    <vuln:summary>Cach? Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0498">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0498</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-10T07:17:40.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=7" xml:lang="en">20030701 Caché Insecure Installation File and Directory Permissions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/" xml:lang="en">https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/</vuln:reference>
    </vuln:references>
    <vuln:summary>Cach? Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0499">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:0.17.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mantis:mantis:0.17.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0499</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-12-07T21:59:23.690-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="https://www.debian.org/security/2003/dsa-335" xml:lang="en">DSA-335</vuln:reference>
    </vuln:references>
    <vuln:summary>Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0500">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.9_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.9_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0500</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:28.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html" xml:lang="en">20030618 SQL Inject in ProFTPD login against Postgresql using mod_sql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-338" xml:lang="en">DSA-338</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0501">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0501</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A328" name="oval:org.mitre.oval:def:328"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105621758104242" xml:lang="en">20030620 Linux /proc sensitive information disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0502">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3g"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3g</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0502</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:41.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" xml:lang="en">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0015.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0015.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0503">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0503</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:44.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105725489003575&amp;w=2" xml:lang="en">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105724538222772&amp;w=2" xml:lang="en">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html" xml:lang="en">http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0504">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14.003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14.003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0504</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:45.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000697" xml:lang="en">CLA-2003:697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105718361607981&amp;w=2" xml:lang="en">20030702 [KSA-003] Cross Site Scripting Vulnerability in Phpgroupware</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-365" xml:lang="en">DSA-365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:077" xml:lang="en">MDKSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.security-corporation.com/articles-20030702-005.html" xml:lang="en">http://www.security-corporation.com/articles-20030702-005.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0505">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:netmeeting:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:netmeeting:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0505</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:47.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105716650021546&amp;w=2" xml:lang="en">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7931" xml:lang="en">7931</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0506">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:netmeeting:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:netmeeting:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0506</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:48.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105716650021546&amp;w=2" xml:lang="en">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0507">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0507</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:49.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105716669921775&amp;w=2" xml:lang="en">20030702 CORE-2003-0305-03: Active Directory Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?kbid=319709" xml:lang="en">Q319709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/594108" xml:lang="en">VU#594108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7930" xml:lang="en">7930</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0508">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0508</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:50.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105709569312583&amp;w=2" xml:lang="en">20030701 [sec-labs] Adobe Acrobat Reader &lt;=5.0.7 Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105785749721291&amp;w=2" xml:lang="en">20030709 Acroread 5.0.7 buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0509">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cyberstrong:eshop:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cyberstrong:eshop:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0509</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105709450711395&amp;w=2" xml:lang="en">20030701 CyberStrong Shopping Cart - Advisory &amp; Exploit Code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007092" xml:lang="en">1007092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/14101" xml:lang="en">14101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/14103" xml:lang="en">14103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/14112" xml:lang="en">14112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12485" xml:lang="en">cyberstrongeshop-multiple-sql-injection(12485)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0510">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.29"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.30"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.31"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.32"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.33"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.34"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.35"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.36"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.37"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.38"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.39"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.40"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.41"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.42"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.43"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.44"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.45"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.46"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.48"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.49"/>
        <cpe-lang:fact-ref name="cpe:/a:ezbounce:ezbounce:1.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.0</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.1</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.2</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.3</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.4</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.5</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.6</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.7</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.8</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.9</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.10</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.11</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.12</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.13</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.14</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.15</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.16</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.17</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.18</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.19</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.20</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.21</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.22</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.23</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.24</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.25</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.26</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.27</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.28</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.29</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.30</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.31</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.32</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.33</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.34</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.35</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.36</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.37</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.38</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.39</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.40</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.41</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.42</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.43</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.44</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.45</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.46</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.47</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.48</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.49</vuln:product>
      <vuln:product>cpe:/a:ezbounce:ezbounce:1.50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0510</vuln:cve-id>
    <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:52.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://druglord.freelsd.org/ezbounce/" xml:lang="en">http://druglord.freelsd.org/ezbounce/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105709355110281&amp;w=2" xml:lang="en">20030701 ezbounce[v1.0-(1.04a/1.50pre6)]: remote format string exploit.</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0511">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%284%29ja"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%284%29ja1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%288%29ja"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2811%29ja"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.2%284%29ja</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%284%29ja1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%288%29ja</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2811%29ja</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0511</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5834" name="oval:org.mitre.oval:def:5834"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0055.html" xml:lang="en">20030728 Cisco Aironet AP 1100 Malformed HTTP Request Crash Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030728-ap1x00.shtml" xml:lang="en">20030728 HTTP GET Vulnerability in AP1x00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm" xml:lang="en">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0512">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2824%29s1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2824.2%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2811%29ja1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814.5%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814.5%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2815%29zn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2815.1%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2816%29b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2816.1%29b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.0%2824%29s1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2824.2%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2811%29ja1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814.5%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814.5%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2815%29zn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2815.1%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2816%29b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2816.1%29b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0512</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:10.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5824" name="oval:org.mitre.oval:def:5824"/>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0056.html" xml:lang="en">20030728 Cisco Aironet AP1100 Valid Account Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml" xml:lang="en">20030724 Enumerating Locally Defined Users in Cisco IOS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/886796" xml:lang="en">VU#886796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm" xml:lang="en">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0513">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0513</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:30.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0514">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:1.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0514</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:31.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0515">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:teapop:teapop:0.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:teapop:teapop:0.3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:teapop:teapop:0.3.4</vuln:product>
      <vuln:product>cpe:/a:teapop:teapop:0.3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0515</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:27.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-347" xml:lang="en">DSA-347</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0516">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gert_doering:mgetty:1.1.28"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gert_doering:mgetty:1.1.28</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0516</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:29.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" xml:lang="en">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</vuln:reference>
    </vuln:references>
    <vuln:summary>cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0517">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gert_doering:mgetty:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:gert_doering:mgetty:1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:gert_doering:mgetty:1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:gert_doering:mgetty:1.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:gert_doering:mgetty:1.1.28"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gert_doering:mgetty:1.1.19</vuln:product>
      <vuln:product>cpe:/a:gert_doering:mgetty:1.1.20</vuln:product>
      <vuln:product>cpe:/a:gert_doering:mgetty:1.1.21</vuln:product>
      <vuln:product>cpe:/a:gert_doering:mgetty:1.1.22</vuln:product>
      <vuln:product>cpe:/a:gert_doering:mgetty:1.1.28</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0517</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:31.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" xml:lang="en">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</vuln:reference>
    </vuln:references>
    <vuln:summary>faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0518">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0518</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:29.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-07/0034.html" xml:lang="en">20030704 MacOSX - crash screensaver locked with password and get the desktop back</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-07/0187.html" xml:lang="en">20030715 FIXED: MacOSX - crash screensaver locked with password and get thedesktop back</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=120232" xml:lang="en">http://docs.info.apple.com/article.html?artnum=120232</vuln:reference>
    </vuln:references>
    <vuln:summary>The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0519">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0519</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:31.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006286.html" xml:lang="en">20030707 Internet Explorer 6 DoS Bug</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0520">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cerulean_studios:trillian:0.74"/>
        <cpe-lang:fact-ref name="cpe:/a:cerulean_studios:trillian:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cerulean_studios:trillian:0.74</vuln:product>
      <vuln:product>cpe:/a:cerulean_studios:trillian:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0520</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:54.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105735714318026&amp;w=2" xml:lang="en">20030704 Trillian Remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8107" xml:lang="en">8107</vuln:reference>
    </vuln:references>
    <vuln:summary>Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0521">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:6.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:6.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:6.4.2_stable_48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cpanel:cpanel:5.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:5.3</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:6.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:6.2</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:6.4</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:6.4.1</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:6.4.2</vuln:product>
      <vuln:product>cpe:/a:cpanel:cpanel:6.4.2_stable_48</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0521</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:55.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105760556627616&amp;w=2" xml:lang="en">20030706 cPanel Malicious HTML Tags Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0522">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5003r"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5004"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:2"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:2br000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:early_impact:productcart:1.5</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5003r</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5004</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:2</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:2br000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0522</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:56.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105733145930031&amp;w=2" xml:lang="en">20030704 Another ProductCart SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105760660928715&amp;w=2" xml:lang="en">20030705 Re: Another ProductCart SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0523">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5003r"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5004"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:2"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:2br000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:early_impact:productcart:1.5</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5003r</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5004</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:2</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:2br000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0523</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:58.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105761696706800&amp;w=2" xml:lang="en">20030705 ProductCart XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0524">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:knoppix:knoppix:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:knoppix:knoppix:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0524</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:34:59.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105769387706906&amp;w=2" xml:lang="en">20030708 Qt temporary files race condition in Knoppix 3.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0525">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0525</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:46.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A319" name="oval:org.mitre.oval:def:319"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a072303-1.txt" xml:lang="en">A072303-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-029" xml:lang="en">MS03-029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12701" xml:lang="en">winnt-file-management-dos(12701)</vuln:reference>
    </vuln:references>
    <vuln:summary>The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0526">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:isa_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:fp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0526</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:46.677-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A117" name="oval:org.mitre.oval:def:117"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html" xml:lang="en">20030716 ISA Server - Error Page Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html" xml:lang="en">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105838519729525&amp;w=2" xml:lang="en">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105838862201266&amp;w=2" xml:lang="en">20030716 ISA Server - Error Page Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105838590030409&amp;w=2" xml:lang="en">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://pivx.com/larholm/adv/TL006" xml:lang="en">http://pivx.com/larholm/adv/TL006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-028" xml:lang="en">MS03-028</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0528">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0528</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A127" name="oval:org.mitre.oval:def:127"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2884" name="oval:org.mitre.oval:def:2884"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2968" name="oval:org.mitre.oval:def:2968"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3966" name="oval:org.mitre.oval:def:3966"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0100.html" xml:lang="en">20030911 NSFOCUS SA2003-06 : Microsoft Windows RPC DCOM Interface Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106407417011430&amp;w=2" xml:lang="en">20030920 The Analysis of RPC Long Filename Heap Overflow AND a Way to Write  Universal Heap Overflow of Windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-23.html" xml:lang="en">CA-2003-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/254236" xml:lang="en">VU#254236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nsfocus.com/english/homepage/research/0306.htm" xml:lang="en">http://www.nsfocus.com/english/homepage/research/0306.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039" xml:lang="en">MS03-039</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0530">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0530</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:49.037-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007538" xml:lang="en">1007538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-22.html" xml:lang="en">CA-2003-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/548964" xml:lang="en">VU#548964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8454" xml:lang="en">8454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032" xml:lang="en">MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12962" xml:lang="en">ie-br549-activex-bo(12962)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0531">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0531</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:49.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-22.html" xml:lang="en">CA-2003-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/205148" xml:lang="en">VU#205148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lac.co.jp/security/english/snsadv_e/67_e.html" xml:lang="en">http://www.lac.co.jp/security/english/snsadv_e/67_e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8457" xml:lang="en">8457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032" xml:lang="en">MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12961" xml:lang="en">ie-cache-script-injection(12961)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0532">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0532</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:50.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html" xml:lang="en">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106149026621753&amp;w=2" xml:lang="en">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20030820.html" xml:lang="en">http://www.eeye.com/html/Research/Advisories/AD20030820.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/865940" xml:lang="en">VU#865940</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032" xml:lang="en">MS03-032</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0533">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:netmeeting"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:netmeeting</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0533</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:50.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A883" name="oval:org.mitre.oval:def:883"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A898" name="oval:org.mitre.oval:def:898"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A919" name="oval:org.mitre.oval:def:919"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html" xml:lang="en">20040413 EEYE: Windows Local Security Authority Service Remote Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108325860431471&amp;w=2" xml:lang="en">20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20040413C.html" xml:lang="en">AD20040413C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/753212" xml:lang="en">VU#753212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10108" xml:lang="en">10108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15699" xml:lang="en">win-lsass-bo(15699)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0535">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xblockout:xbl:1.0i"/>
        <cpe-lang:fact-ref name="cpe:/a:xblockout:xbl:1.0k"/>
        <cpe-lang:fact-ref name="cpe:/a:xblockout:xbl:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xblockout:xbl:1.0i</vuln:product>
      <vuln:product>cpe:/a:xblockout:xbl:1.0k</vuln:product>
      <vuln:product>cpe:/a:xblockout:xbl:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0535</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:32.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006386.html" xml:lang="en">20030708 Fwd: xbl vulnerabilty</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-345" xml:lang="en">DSA-345</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0536">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpsysinfo:phpsysinfo:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpsysinfo:phpsysinfo:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpsysinfo:phpsysinfo:2.0</vuln:product>
      <vuln:product>cpe:/a:phpsysinfo:phpsysinfo:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0536</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:07.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105128606513226&amp;w=2" xml:lang="en">20030425 Unauthorized reading files on phpSysInfo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015" xml:lang="en">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-346" xml:lang="en">DSA-346</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0537">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:daiki_ueno:liece_emacs_irc_client:2.0_0.2003-05-27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:daiki_ueno:liece_emacs_irc_client:2.0_0.2003-05-27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0537</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:34.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-341" xml:lang="en">DSA-341</vuln:reference>
    </vuln:references>
    <vuln:summary>The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0538">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozart:mozart:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozart:mozart:1.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozart:mozart:1.2.3</vuln:product>
      <vuln:product>cpe:/a:mozart:mozart:1.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0538</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:33.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-342" xml:lang="en">DSA-342</vuln:reference>
    </vuln:references>
    <vuln:summary>The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0539">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ddskk:ddskk:11.6_.rel.0"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:daredevil_skk:11.3.2::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:daredevil_skk:11.3.5::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:daredevil_skk:11.6.0-6::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:daredevil_skk:11.6.0-8::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:daredevil_skk:11.6.0-10::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:ddskk-xemacs:11.6.0-6::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:ddskk-xemacs:11.6.0-8::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:ddskk-xemacs:11.6.0-10::noarch"/>
        <cpe-lang:fact-ref name="cpe:/a:skk:skk:10.62a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ddskk:ddskk:11.6_.rel.0</vuln:product>
      <vuln:product>cpe:/a:redhat:daredevil_skk:11.3.2::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:daredevil_skk:11.3.5::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:daredevil_skk:11.6.0-6::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:daredevil_skk:11.6.0-8::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:daredevil_skk:11.6.0-10::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:ddskk-xemacs:11.6.0-6::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:ddskk-xemacs:11.6.0-8::noarch</vuln:product>
      <vuln:product>cpe:/a:redhat:ddskk-xemacs:11.6.0-10::noarch</vuln:product>
      <vuln:product>cpe:/a:skk:skk:10.62a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0539</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A28" name="oval:org.mitre.oval:def:28"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-343" xml:lang="en">DSA-343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-242.html" xml:lang="en">RHSA-2003:242</vuln:reference>
    </vuln:references>
    <vuln:summary>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0540">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1999-09-06"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:1999-12-31"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:2000-02-28"/>
        <cpe-lang:fact-ref name="cpe:/a:wietse_venema:postfix:2001-11-15"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wietse_venema:postfix:1.0.21</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1.1.11</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1.1.12</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1999-09-06</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:1999-12-31</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:2000-02-28</vuln:product>
      <vuln:product>cpe:/a:wietse_venema:postfix:2001-11-15</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:7.0</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0540</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A544" name="oval:org.mitre.oval:def:544"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717" xml:lang="en">CLA-2003:717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-August/007693.html" xml:lang="en">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106001525130257&amp;w=2" xml:lang="en">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106029188614704&amp;w=2" xml:lang="en">2003-0029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-363" xml:lang="en">DSA-363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/895508" xml:lang="en">VU#895508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3517.html" xml:lang="en">ESA-20030804-019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081" xml:lang="en">MDKSA-2003:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_033_postfix.html" xml:lang="en">SuSE-SA:2003:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-251.html" xml:lang="en">RHSA-2003:251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8333" xml:lang="en">8333</vuln:reference>
    </vuln:references>
    <vuln:summary>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0541">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gtkhtml:1.1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gtkhtml:1.1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0541</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A148" name="oval:org.mitre.oval:def:148"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" xml:lang="en">CLA-2003:737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-710" xml:lang="en">DSA-710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:093" xml:lang="en">MDKSA-2003:093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-264.html" xml:lang="en">RHSA-2003:264</vuln:reference>
    </vuln:references>
    <vuln:summary>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0542">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.14</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0542</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:20.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3799" name="oval:org.mitre.oval:def:3799"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A863" name="oval:org.mitre.oval:def:863"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A864" name="oval:org.mitre.oval:def:864"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9458" name="oval:org.mitre.oval:def:9458"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" xml:lang="en">SCOSA-2004.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031203-01-U.asc" xml:lang="en">20031203-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://httpd.apache.org/dist/httpd/Announcement2.html" xml:lang="en">http://httpd.apache.org/dist/httpd/Announcement2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00045.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106761802305141&amp;w=2" xml:lang="en">20031031 GLSA:  apache (200310-04)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" xml:lang="en">SSRT090208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101444-1" xml:lang="en">101444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" xml:lang="en">101841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/434566" xml:lang="en">VU#434566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/549142" xml:lang="en">VU#549142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103" xml:lang="en">MDKSA-2003:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-320.html" xml:lang="en">RHSA-2003:320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-360.html" xml:lang="en">RHSA-2003:360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-405.html" xml:lang="en">RHSA-2003:405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-015.html" xml:lang="en">RHSA-2004:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-816.html" xml:lang="en">RHSA-2005:816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6079" xml:lang="en">HPSBUX0311-301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342674" xml:lang="en">20031028 [OpenPKG-SA-2003.046] OpenPKG Security Advisory (apache)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8911" xml:lang="en">8911</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13400" xml:lang="en">apache-modalias-modrewrite-bo(13400)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0543">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0543</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.100-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4254" name="oval:org.mitre.oval:def:4254"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5292" name="oval:org.mitre.oval:def:5292"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1" xml:lang="en">201029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-26.html" xml:lang="en">CA-2003-26</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-393" xml:lang="en">DSA-393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-394" xml:lang="en">DSA-394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/255484" xml:lang="en">VU#255484</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html" xml:lang="en">ESA-20030930-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-291.html" xml:lang="en">RHSA-2003:291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-292.html" xml:lang="en">RHSA-2003:292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8732" xml:lang="en">8732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/3900" xml:lang="en">ADV-2006-3900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0544">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0544</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.223-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4574" name="oval:org.mitre.oval:def:4574"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1" xml:lang="en">201029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-26.html" xml:lang="en">CA-2003-26</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-393" xml:lang="en">DSA-393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-394" xml:lang="en">DSA-394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/380864" xml:lang="en">VU#380864</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html" xml:lang="en">ESA-20030930-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-291.html" xml:lang="en">RHSA-2003:291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-292.html" xml:lang="en">RHSA-2003:292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8732" xml:lang="en">8732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/3900" xml:lang="en">ADV-2006-3900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/43041" xml:lang="en">openssl-asn1-sslclient-dos(43041)</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0545">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0545</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.350-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2590" name="oval:org.mitre.oval:def:2590"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-26.html" xml:lang="en">CA-2003-26</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-394" xml:lang="en">DSA-394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/935264" xml:lang="en">VU#935264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-292.html" xml:lang="en">RHSA-2003:292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8732" xml:lang="en">8732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/3900" xml:lang="en">ADV-2006-3900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0546">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:up2date:3.0.7-1::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:up2date:3.0.7-1::i386_gnome"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:up2date:3.1.23-1::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:up2date:3.1.23-1::i386_gnome"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:up2date:3.0.7-1::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:up2date:3.0.7-1::i386_gnome</vuln:product>
      <vuln:product>cpe:/a:redhat:up2date:3.1.23-1::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:up2date:3.1.23-1::i386_gnome</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0546</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A631" name="oval:org.mitre.oval:def:631"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106036724315539&amp;w=2" xml:lang="en">RHSA-2003:255</vuln:reference>
    </vuln:references>
    <vuln:summary>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0547">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.4.0.7.13::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.4.1.3.5::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.5</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.6</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.4.0.7.13::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.4.1.3.5::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0547</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A112" name="oval:org.mitre.oval:def:112"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" xml:lang="en">CLA-2003:729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" xml:lang="en">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106194792924122&amp;w=2" xml:lang="en">20030824 [slackware-security]  GDM security update (SSA:2003-236-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-258.html" xml:lang="en">RHSA-2003:258</vuln:reference>
    </vuln:references>
    <vuln:summary>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0548">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.0_beta2.45::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.0_beta2.45::ppc"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.2.3.1.20::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.2.3.1.20::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.2.3.1.22::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.4.0.7.13::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.4.1.3.5::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gdm:2.2.0</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.5</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.6</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.0_beta2.45::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.0_beta2.45::ppc</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.2.3.1.20::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.2.3.1.20::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.2.3.1.22::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.4.0.7.13::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.4.1.3.5::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0548</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A113" name="oval:org.mitre.oval:def:113"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" xml:lang="en">CLA-2003:729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" xml:lang="en">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-258.html" xml:lang="en">RHSA-2003:258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-259.html" xml:lang="en">RHSA-2003:259</vuln:reference>
    </vuln:references>
    <vuln:summary>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0549">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.0_beta2.45::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.0_beta2.45::ppc"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.2.3.1.20::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.2.3.1.20::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.2.3.1.22::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.4.0.7.13::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kdebase:2.4.1.3.5::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gdm:2.2.0</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.5</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.6</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.0_beta2.45::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.0_beta2.45::ppc</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.2.3.1.20::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.2.3.1.20::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.2.3.1.22::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.4.0.7.13::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:kdebase:2.4.1.3.5::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0549</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A129" name="oval:org.mitre.oval:def:129"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" xml:lang="en">CLA-2003:729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" xml:lang="en">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-258.html" xml:lang="en">RHSA-2003:258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-259.html" xml:lang="en">RHSA-2003:259</vuln:reference>
    </vuln:references>
    <vuln:summary>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0550">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0550</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A380" name="oval:org.mitre.oval:def:380"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0551">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0551</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A384" name="oval:org.mitre.oval:def:384"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0552">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0552</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A385" name="oval:org.mitre.oval:def:385"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0553">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:7.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:navigator:7.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0553</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:13.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf" xml:lang="en">http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105820193406838&amp;w=2" xml:lang="en">20030714 Netscape 7.02 Client Detection Tool plug-in buffer overrun</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0554">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:neomodus:direct_connect:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neomodus:direct_connect:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0554</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:14.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006505.html" xml:lang="en">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105820316708258&amp;w=2" xml:lang="en">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</vuln:reference>
    </vuln:references>
    <vuln:summary>NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0555">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:5.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:imagemagick:imagemagick:5.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0555</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:16.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105820576111599&amp;w=2" xml:lang="en">20030714 ImageMagick's Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0556">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:polycom:mgc-100"/>
        <cpe-lang:fact-ref name="cpe:/h:polycom:mgc-25:5.51.21"/>
        <cpe-lang:fact-ref name="cpe:/h:polycom:mgc-25:5.51.211"/>
        <cpe-lang:fact-ref name="cpe:/h:polycom:mgc-50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:polycom:mgc-100</vuln:product>
      <vuln:product>cpe:/h:polycom:mgc-25:5.51.21</vuln:product>
      <vuln:product>cpe:/h:polycom:mgc-25:5.51.211</vuln:product>
      <vuln:product>cpe:/h:polycom:mgc-50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0556</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:17.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006494.html" xml:lang="en">20030712 DoS - Polycom MGC 25 Control Port</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105804648003163&amp;w=2" xml:lang="en">20030712 DoS - Polycom MGC 25 Control Port</vuln:reference>
    </vuln:references>
    <vuln:summary>Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0557">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lagarde:storefront:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lagarde:storefront:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0557</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:18.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105804683203384&amp;w=2" xml:lang="en">20030712 ZH2003-3SA (security advisory): Storefront sql injection: users</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0558">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:leapware:leapftp:2.7.3.600"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:leapware:leapftp:2.7.3.600</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0558</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:19.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105795219412333&amp;w=2" xml:lang="en">20030711 LeapFTP remote buffer overflow exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0559">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpforum:phpforum:2.0_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpforum:phpforum:2.0_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0559</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:21.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105787021803729&amp;w=2" xml:lang="en">20030710 PHP-Include-Hack-Possibility in phpforum 2 RC-1</vuln:reference>
    </vuln:references>
    <vuln:summary>mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0560">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtual_programming:vp-asp:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtual_programming:vp-asp:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0560</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:22.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105733277731084&amp;w=2" xml:lang="en">20030704 VPASP SQL Injection Vulnerability &amp; Exploit CODE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8159" xml:lang="en">8159</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0561">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:iglooftp:iglooftp_pro:3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:iglooftp:iglooftp_pro:3.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0561</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:23.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0010.html" xml:lang="en">20030707 Multiple Buffer Overflows in IglooFTP PRO</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105769805311484&amp;w=2" xml:lang="en">20030707 Multiple Buffer Overflows in IglooFTP PRO</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0562">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:5.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:5.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:6.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:novell:netware:5.1</vuln:product>
      <vuln:product>cpe:/o:novell:netware:5.1:sp4</vuln:product>
      <vuln:product>cpe:/o:novell:netware:5.1:sp6</vuln:product>
      <vuln:product>cpe:/o:novell:netware:6.0</vuln:product>
      <vuln:product>cpe:/o:novell:netware:6.0:sp1</vuln:product>
      <vuln:product>cpe:/o:novell:netware:6.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0562</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:25.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0041.html" xml:lang="en">20030723 Buffer Overflow in Netware Web Server PERL Handler</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105897561229347&amp;w=2" xml:lang="en">20030723 NOVL-2003-2966549 - Enterprise Web Server PERL Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105897724931665&amp;w=2" xml:lang="en">20030723 Buffer Overflow in Netware Web Server PERL Handler</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/servlet/tidfinder/2966549" xml:lang="en">http://support.novell.com/servlet/tidfinder/2966549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/185593" xml:lang="en">VU#185593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.protego.dk/advisories/200301.html" xml:lang="en">http://www.protego.dk/advisories/200301.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0564">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hitachi:groupmax_mail_-_security_option:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:pki_runtime_library"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:groupmax_mail_-_security_option:6.0</vuln:product>
      <vuln:product>cpe:/a:hitachi:pki_runtime_library</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0564</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11462" name="oval:org.mitre.oval:def:11462"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A872" name="oval:org.mitre.oval:def:872"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A914" name="oval:org.mitre.oval:def:914"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040402-01-U.asc" xml:lang="en">20040402-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108448379429944&amp;w=2" xml:lang="en">SSRT4722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109900315219363&amp;w=2" xml:lang="en">FLSA:2089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/428230" xml:lang="en">VU#428230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" xml:lang="en">MDKSA-2004:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-110.html" xml:lang="en">RHSA-2004:110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-112.html" xml:lang="en">RHSA-2004:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8981" xml:lang="en">8981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2003/006489/smime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2003/006489/smime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13603" xml:lang="en">smime-asn1-bo(13603)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0565">
    <vuln:cve-id>CVE-2003-0565</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/927278" xml:lang="en">VU#927278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2003/006489/x400.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2003/006489/x400.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0567">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1cc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2sa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0w5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ax"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ay"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1dc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ea"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1eb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ec"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ev"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ew"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ex"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ey"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1m"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ye"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2cx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2cy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2dd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2dx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ja"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ya"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ym"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yo"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ys"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2za"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ze"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zj"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:optical_networking_systems_software:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:optical_networking_systems_software:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:optical_networking_systems_software:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:optical_networking_systems_software:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:optical_networking_systems_software:3.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:optical_networking_systems_software:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ons_15454_optical_transport_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:optical_networking_systems_software:3.0</vuln:product>
      <vuln:product>cpe:/a:cisco:optical_networking_systems_software:3.1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:optical_networking_systems_software:3.2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:optical_networking_systems_software:3.3.0</vuln:product>
      <vuln:product>cpe:/a:cisco:optical_networking_systems_software:3.4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:optical_networking_systems_software:4.0.0</vuln:product>
      <vuln:product>cpe:/h:cisco:ons_15454_optical_transport_platform</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1cc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2sa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0dc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0w5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ax</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ay</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1dc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ea</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1eb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ec</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ev</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ew</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ex</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ey</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1m</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ye</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2cx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2cy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2dd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2dx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ja</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ya</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ym</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yo</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ys</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2za</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ze</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zj</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0567</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:17.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5603" name="oval:org.mitre.oval:def:5603"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006743.html" xml:lang="en">20030718 (no subject)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-15.html" xml:lang="en">CA-2003-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-17.html" xml:lang="en">CA-2003-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml" xml:lang="en">20030717 IOS Interface Blocked by IPv4 Packet</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/411332" xml:lang="en">VU#411332</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0568">
    <vuln:cve-id>CVE-2003-0568</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.853-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.853-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0569">
    <vuln:cve-id>CVE-2003-0569</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.887-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.887-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0570">
    <vuln:cve-id>CVE-2003-0570</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.900-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.917-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0571">
    <vuln:cve-id>CVE-2003-0571</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.933-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.933-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0572">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0572</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" xml:lang="en">20030701-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12635" xml:lang="en">irix-nsd-map-dos(12635)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0573">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0573</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:40.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" xml:lang="en">20030701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0574">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0574</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:42.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030702-01-P" xml:lang="en">20030702-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0575">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0575</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030704-01-P" xml:lang="en">20030704-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105958240709302&amp;w=2" xml:lang="en">20030730 [LSD] IRIX nsd remote buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-130.shtml" xml:lang="en">N-130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/682900" xml:lang="en">VU#682900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8304" xml:lang="en">8304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12763" xml:lang="en">irix-authunix-nsd-bo(12763)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the name services daemon (nsd) in SGI IRIX 6.5.x through 6.5.21f, and possibly earlier versions, allows attackers to gain root privileges via the AUTH_UNIX gid list.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0576">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0576</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:42.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030801-01-P" xml:lang="en">20030801-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030801-02-P" xml:lang="en">20030801-02-P</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, a different vulnerability than CVE-2003-0619.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0577">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59r"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:pre0.59s"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59r</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:pre0.59s</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0577</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:42.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt" xml:lang="en">CSSA-2004-002.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000695" xml:lang="en">CLA-2003:695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:078" xml:lang="en">MDKSA-2003:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/306903" xml:lang="en">20030116 Re[2]: Local/remote mpg123 exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6629" xml:lang="en">6629</vuln:reference>
    </vuln:references>
    <vuln:summary>mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0578">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:u2_universe:10.0.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:u2_universe:10.0.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0578</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:29.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html" xml:lang="en">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839150004682&amp;w=2" xml:lang="en">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</vuln:reference>
    </vuln:references>
    <vuln:summary>cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0579">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:u2_universe:10.0.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:u2_universe:10.0.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0579</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:30.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html" xml:lang="en">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105838948002337&amp;w=2" xml:lang="en">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</vuln:reference>
    </vuln:references>
    <vuln:summary>uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0580">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:u2_universe:10.0.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:u2_universe:10.0.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0580</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:31.770-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0028.html" xml:lang="en">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839042603476&amp;w=2" xml:lang="en">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0581">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfstt:xfstt:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfstt:xfstt:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfstt:xfstt:1.2.1</vuln:product>
      <vuln:product>cpe:/a:xfstt:xfstt:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0581</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:33.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105829691405446&amp;w=2" xml:lang="en">20030714 xfstt-1.4 vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-360" xml:lang="en">DSA-360</vuln:reference>
    </vuln:references>
    <vuln:summary>X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0582">
    <vuln:cve-id>CVE-2003-0582</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:43.367-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0504.  Reason: This candidate is a duplicate of CVE-2003-0504.  Notes: All CVE users should reference CVE-2003-0504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0583">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tolis_group:bru:17.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tolis_group:bru:17.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0583</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:34.520-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105846288808846&amp;w=2" xml:lang="en">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0584">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tolis_group:bru:17.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tolis_group:bru:17.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0584</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:35.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105846288808846&amp;w=2" xml:lang="en">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0585">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brooky:estore:1.0.2b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brooky:estore:1.0.2b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0585</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:37.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105845898003616&amp;w=2" xml:lang="en">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0586">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brooky:estore:1.0.2b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brooky:estore:1.0.2b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0586</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:38.223-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105845898003616&amp;w=2" xml:lang="en">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:summary>Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0587">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:infopop:ultimate_bulletin_board:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:infopop:ultimate_bulletin_board:6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0587</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:39.270-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839276105934&amp;w=2" xml:lang="en">20030716 Changing UBB cookie allows account hijack</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0588">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digi-fx:digi-news:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digi-fx:digi-news:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0588</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:40.410-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839007002993&amp;w=2" xml:lang="en">20030716 Digi-news and Digi-ads version 1.1 admin access without password</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0589">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digi-fx:digi-news:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digi-fx:digi-news:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0589</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:42.053-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839007002993&amp;w=2" xml:lang="en">20030716 Digi-news and Digi-ads version 1.1 admin access without password</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0590">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:splatt:splatt_forum"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:splatt:splatt_forum</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0590</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:43.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105830019209609&amp;w=2" xml:lang="en">20030715 Splatt Forum html injection code in post icon</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://members.fortunecity.it/lethalman2002/bugs/splatt.html" xml:lang="en">http://members.fortunecity.it/lethalman2002/bugs/splatt.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0591">
    <vuln:cve-id>CVE-2003-0591</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:44.697-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a duplicate number that was created during the refinement phase.  Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0592">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror_embedded:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:konqueror:2.1.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:2.2.2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.3</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.0.5</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.1.1</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror:3.1.2</vuln:product>
      <vuln:product>cpe:/a:kde:konqueror_embedded:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0592</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:11.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A823" name="oval:org.mitre.oval:def:823"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-459" xml:lang="en">DSA-459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:022" xml:lang="en">MDKSA-2004:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-074.html" xml:lang="en">RHSA-2004:074</vuln:reference>
    </vuln:references>
    <vuln:summary>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0593">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.0::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.0.2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.1.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.1.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.12::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.4::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.5::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.6::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.10::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.3::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11b"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11j"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20_beta1_build2981"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.21"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.22"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.0::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.0::mac</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.0.2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.1.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.1.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.12</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:5.12::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.4::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.5::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.6</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.6::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.10::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.3::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.10</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11b</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11j</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20_beta1_build2981</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.21</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.22</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0593</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:43.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0594">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0594</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:12.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A873" name="oval:org.mitre.oval:def:873"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A917" name="oval:org.mitre.oval:def:917"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9826" name="oval:org.mitre.oval:def:9826"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" xml:lang="en">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" xml:lang="en">MDKSA-2004:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-112.html" xml:lang="en">RHSA-2004:112</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0595">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:witango:tango_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:witango:witango_server:5.0.1.061"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:witango:tango_server:2000</vuln:product>
      <vuln:product>cpe:/a:witango:witango_server:5.0.1.061</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0595</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:45.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0038.html" xml:lang="en">20030718 Witango &amp; Tango 2000 Application Server Remote System Buffer Overrun</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0596">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fdclone:fdclone:2.00a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fdclone:fdclone:2.00a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0596</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-12-07T21:59:24.800-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=186219" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=186219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="https://www.debian.org/security/2003/dsa-352" xml:lang="en">DSA-352</vuln:reference>
    </vuln:references>
    <vuln:summary>FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if they already exist, which allows local users to read or modify files of other fdclone users by creating the directory ahead of time.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0597">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0597</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:45.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105889063714201&amp;w=2" xml:lang="en">CSSA-2003-SCO-11</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0598">
    <vuln:cve-id>CVE-2003-0598</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:46.477-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0657.  Reason: This candidate is a reservation duplicate of CVE-2003-0657.  Notes: All CVE users should reference CVE-2003-0657 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0599">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14.004"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.16prerc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14.004</vuln:product>
      <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.16prerc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0599</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:44.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html" xml:lang="en">http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-365" xml:lang="en">DSA-365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpgroupware.org" xml:lang="en">http://www.phpgroupware.org</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web document root.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0601">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0601</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=25631" xml:lang="en">http://docs.info.apple.com/article.html?artnum=25631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8266" xml:lang="en">8266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12728" xml:lang="en">macos-workgroup-gain-access(12728)</vuln:reference>
    </vuln:references>
    <vuln:summary>Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0602">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0602</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:45.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000653" xml:lang="en">CLA-2003:653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bugzilla.org/security/2.16.2/" xml:lang="en">http://www.bugzilla.org/security/2.16.2/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6861" xml:lang="en">6861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6868" xml:lang="en">6868</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0603">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0603</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:45.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000653" xml:lang="en">CLA-2003:653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bugzilla.org/security/2.16.2/" xml:lang="en">http://www.bugzilla.org/security/2.16.2/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7412" xml:lang="en">7412</vuln:reference>
    </vuln:references>
    <vuln:summary>Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0604">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_player:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0604</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-08-13T17:47:19.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105899261818572&amp;w=2" xml:lang="en">20030723 Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105906867322856&amp;w=2" xml:lang="en">20030723 Re: Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105899408520292&amp;w=2" xml:lang="en">20030723 Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105906261314411&amp;w=2" xml:lang="en">20030723 Re: Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.malware.com/once.again!.html" xml:lang="en">http://www.malware.com/once.again!.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pivx.com/larholm/unpatched/" xml:lang="en">http://www.pivx.com/larholm/unpatched/</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0605">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0605</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1118" name="oval:org.mitre.oval:def:1118"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A494" name="oval:org.mitre.oval:def:494"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006851.html" xml:lang="en">20030721 Microsoft Windows 2000 RPC DCOM Interface DOS AND Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105880332428706&amp;w=2" xml:lang="en">20030720 Microsoft Windows 2000 RPC DCOM Interface DOS AND Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-19.html" xml:lang="en">CA-2003-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-23.html" xml:lang="en">CA-2003-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/326746" xml:lang="en">VU#326746</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039" xml:lang="en">MS03-039</vuln:reference>
    </vuln:references>
    <vuln:summary>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0606">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cvsup:cvsup-mirror:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sup:sup:1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cvsup:cvsup-mirror:1.2</vuln:product>
      <vuln:product>cpe:/a:sup:sup:1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0606</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:49.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-353" xml:lang="en">DSA-353</vuln:reference>
    </vuln:references>
    <vuln:summary>sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0607">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stanley_t._shebs:xconq:7.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stanley_t._shebs:xconq:7.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0607</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-354" xml:lang="en">DSA-354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8307" xml:lang="en">8307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12765" xml:lang="en">xconq-user-display-bo(12765)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0609">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0609</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3601" name="oval:org.mitre.oval:def:3601"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105951760418667&amp;w=2" xml:lang="en">20030729 Solaris ld.so.1 buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55680" xml:lang="en">55680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/07.29.03.txt" xml:lang="en">20030729 Buffer Overflow in Sun Solaris Runtime Linker</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12755" xml:lang="en">sun-ldso1-ldpreload-bo(12755)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0610">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0610</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:49.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" xml:lang="en">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0611">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xtokkaetama:xtokkaetama:1.0_b6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xtokkaetama:xtokkaetama:1.0_b6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0611</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:46.563-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-356" xml:lang="en">DSA-356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8312" xml:lang="en">8312</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0612">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:robert_hyatt:crafty:19.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:robert_hyatt:crafty:19.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0612</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:33.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203541" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203541</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://packages.debian.org/changelogs/pool/non-free/c/crafty/crafty_19.15-1/changelog.txt" xml:lang="en">http://packages.debian.org/changelogs/pool/non-free/c/crafty/crafty_19.15-1/changelog.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009393" xml:lang="en">1009393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009398" xml:lang="en">1009398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/357601" xml:lang="en">20040315 Crafty Game Stack Overflow &amp; Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9893" xml:lang="en">9893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13017" xml:lang="en">crafty-long-argument-bo(13017)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15501" xml:lang="en">crafty-command-line-bo(15501)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0613">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zblast:zblast:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zblast:zblast:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0613</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:19:51.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-369" xml:lang="en">DSA-369</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0614">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2.1_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gallery_project:gallery:1.1</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2.1</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2.1_p1</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2.2</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2.3</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2.4</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.2.5</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.3</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.3.1</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.3.2</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.3.3</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0614</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:36.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=82&amp;mode=thread&amp;order=0&amp;thold=0" xml:lang="en">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=82&amp;mode=thread&amp;order=0&amp;thold=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252092421469&amp;w=2" xml:lang="en">20030902 GLSA:  gallery (200309-06)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-355" xml:lang="en">DSA-355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/330676" xml:lang="en">20030727 Gallery XSS security advisory (with fix and patch instructions)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348641/30/21790/threaded" xml:lang="en">20040101 Re: Gallery v1.3.3 Cross Site Scripting Vulnerabillity</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0615">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.73"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.74"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.75"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.76"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.78"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.79"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.93"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.751"/>
        <cpe-lang:fact-ref name="cpe:/a:cgi.pm:cgi.pm:2.753"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:current"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.73</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.74</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.75</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.76</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.78</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.79</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.93</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.751</vuln:product>
      <vuln:product>cpe:/a:cgi.pm:cgi.pm:2.753</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:1.2</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:1.3</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:current</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0615</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A307" name="oval:org.mitre.oval:def:307"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A470" name="oval:org.mitre.oval:def:470"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000713" xml:lang="en">CLA-2003:713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105880349328877&amp;w=2" xml:lang="en">20030720 CGI.pm vulnerable to Cross-site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106018783704468&amp;w=2" xml:lang="en">20030806 [OpenPKG-SA-2003.036] OpenPKG Security Advisory (perl-www)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=105875211018698&amp;w=2" xml:lang="en">20030720 CGI.pm vulnerable to Cross-site Scripting.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007234" xml:lang="en">1007234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101426-1" xml:lang="en">101426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-155.shtml" xml:lang="en">N-155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-371" xml:lang="en">DSA-371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/246409" xml:lang="en">VU#246409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-256.html" xml:lang="en">RHSA-2003:256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8231" xml:lang="en">8231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:084" xml:lang="en">MDKSA-2003:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12669" xml:lang="en">cgi-startform-xss(12669)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0616">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0616</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-07-23T01:04:36.740-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a073103-1.txt" xml:lang="en">A073103-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" xml:lang="en">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0617">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hugo_rabson:mindi:0.58_r5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hugo_rabson:mindi:0.58_r5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0617</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:53.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252097421549&amp;w=2" xml:lang="en">20030902 GLSA:  mindi (200309-05)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-362" xml:lang="en">DSA-362</vuln:reference>
    </vuln:references>
    <vuln:summary>mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0618">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:perl:suidperl"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:perl:suidperl</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0618</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-431" xml:lang="en">DSA-431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9543" xml:lang="en">9543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15012" xml:lang="en">suidperl-obtain-information(15012)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0619">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0619</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:12.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A386" name="oval:org.mitre.oval:def:386"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105950927708272&amp;w=2" xml:lang="en">20030729 Remote Linux Kernel &lt; 2.4.21 DoS in XDR routine.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0620">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:man:2.3.18</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:2.3.19</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:2.3.20</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:2.4</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:2.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0620</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:35:55.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105951284512898&amp;w=2" xml:lang="en">20030729 man-db[] multiple(4) vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105960276803617&amp;w=2" xml:lang="en">20030730 Re: man-db[] multiple(4) vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-364" xml:lang="en">DSA-364</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0621">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:4.2::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.0.1::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.1::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:tuxedo:6.3</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:6.4</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:6.5</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:7.1</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:8.0</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:4.2::enterprise</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.0.1::enterprise</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.1::enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0621</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106762000607681&amp;w=2" xml:lang="en">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8931" xml:lang="en">8931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13559" xml:lang="en">bea-tuxedo-file-disclosure(13559)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0622">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:4.2::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.0.1::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.1::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:tuxedo:6.3</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:6.4</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:6.5</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:7.1</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:8.0</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:4.2::enterprise</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.0.1::enterprise</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.1::enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0622</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106762000607681&amp;w=2" xml:lang="en">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8931" xml:lang="en">8931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13560" xml:lang="en">bea-tuxedo-device-dos(13560)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0623">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:tuxedo:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:4.2::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.0.1::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.1::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:tuxedo:6.3</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:6.4</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:6.5</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:7.1</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:8.0</vuln:product>
      <vuln:product>cpe:/a:bea:tuxedo:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:4.2::enterprise</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.0.1::enterprise</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.1::enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0623</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106762000607681&amp;w=2" xml:lang="en">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8931" xml:lang="en">8931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13561" xml:lang="en">bea-tuxedo-filename-xss(13561)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0624">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:3.1.8</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0624</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106761926906781&amp;w=2" xml:lang="en">20031031 Corsaire Security Advisory: BEA WebLogic example InteractiveQuery.jsp XSS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8938" xml:lang="en">8938</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13568" xml:lang="en">bea-weblogic-interactivequery-xss(13568)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0625">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfstt:xfstt:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfstt:xfstt:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfstt:xfstt:1.2.1</vuln:product>
      <vuln:product>cpe:/a:xfstt:xfstt:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0625</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:02.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/forum/forum.php?forum_id=2819" xml:lang="en">http://developer.berlios.de/forum/forum.php?forum_id=2819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105941103709264&amp;w=2" xml:lang="en">20030727 [PAPER]: Address relay fingerprinting.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-360" xml:lang="en">DSA-360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8255" xml:lang="en">8255</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0626">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.19"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.20"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.42"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.4</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.19</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.20</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.42</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0626</vuln:cve-id>
    <vuln:published-datetime>2003-11-13T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0042.html" xml:lang="en">20031113 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013652.html" xml:lang="en">20031103 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3610" xml:lang="en">ESB-2003.0786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9037" xml:lang="en">9037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13754" xml:lang="en">peoplesoft-searchcgi-directory-traversal(13754)</vuln:reference>
    </vuln:references>
    <vuln:summary>psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0627">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.42"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.42</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0627</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0042.html" xml:lang="en">20031113 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013652.html" xml:lang="en">20031103 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9038" xml:lang="en">9038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13754" xml:lang="en">peoplesoft-searchcgi-directory-traversal(13754)</vuln:reference>
    </vuln:references>
    <vuln:summary>psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0628">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.19"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.20"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.42"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.4</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.19</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.20</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.42</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0628</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:03.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106874146204158&amp;w=2" xml:lang="en">20031113 Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:summary>PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0629">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.19"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.20"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.42"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.4</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.19</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.20</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.42</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0629</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:04.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106874146204158&amp;w=2" xml:lang="en">20031113 Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0630">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.2.1_pre0"/>
        <cpe-lang:fact-ref name="cpe:/o:atari800:atari800:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:atari800:atari800:1.0.1</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.0.2</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.0.3</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.0.4</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.0.5</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.0.6</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.0.7</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.2</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.2.1</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.2.1_pre0</vuln:product>
      <vuln:product>cpe:/o:atari800:atari800:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0630</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:06.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252128221901&amp;w=2" xml:lang="en">20030902 GLSA:  atari800 (200309-07)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-359" xml:lang="en">DSA-359</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0631">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0631</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:07.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105899875225268&amp;w=2" xml:lang="en">20030723 VMware GSX Server 2.5.1 / Workstation 4.0 (for Linux systems)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1039" xml:lang="en">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1039</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0632">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:applications:10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:applications:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:applications:10.7</vuln:product>
      <vuln:product>cpe:/a:oracle:applications:11.0</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.1</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.2</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.3</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.4</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.6</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.7</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0632</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:09.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105906721920776&amp;w=2" xml:lang="en">20030724 Integrigy Security Alert - Oracle E-Business Suite FNDWRR Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrary code via a long URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0633">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:applications:10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:applications:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:applications:10.7</vuln:product>
      <vuln:product>cpe:/a:oracle:applications:11.0</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.1</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.2</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.3</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.4</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.6</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.7</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0633</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:10.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105906689120237&amp;w=2" xml:lang="en">20030724 Integrigy Security Alert - Oracle E-Business Suite AOL/J Setup Test Information Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8268" xml:lang="en">8268</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0634">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.5_.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.5_.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.5_.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.6_.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.6_.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.7_.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:enterprise_8.1.7_.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:standard_8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:standard_8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:standard_8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:standard_8.1.7_.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:standard_8.1.7_.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:standard_8.1.7_.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:client_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:client_9.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.5_.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.5_.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.5_.1.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.6_.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.6_.1.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.7_.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:enterprise_8.1.7_.1.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:standard_8.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:standard_8.1.6</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:standard_8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:standard_8.1.7_.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:standard_8.1.7_.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:standard_8.1.7_.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:client_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:client_9.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0634</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0105.html" xml:lang="en">20030912 Update to the Oracle EXTPROC advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105914979629857&amp;w=2" xml:lang="en">20030725 Oracle Extproc Buffer Overflow (#NISR25072003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105916455814904&amp;w=2" xml:lang="en">20030725 question about oracle advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=105915485303327&amp;w=2" xml:lang="en">20030725 Oracle Extproc Buffer Overflow (#NISR25072003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/936868" xml:lang="en">VU#936868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8267" xml:lang="en">8267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12721" xml:lang="en">oracle-extproc-bo(12721)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0635">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:ichain:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0635</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:12.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105492852131747&amp;w=2" xml:lang="en">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0636">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:ichain:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0636</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:50.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0637">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:ichain:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0637</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:50.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0638">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.1:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:ichain:2.1</vuln:product>
      <vuln:product>cpe:/a:novell:ichain:2.1:sp1</vuln:product>
      <vuln:product>cpe:/a:novell:ichain:2.1:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0638</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:14.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105492847631711&amp;w=2" xml:lang="en">20030606 NOVL-2003-2966207 - iChain 2.1 Field Patch 3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105492852131747&amp;w=2" xml:lang="en">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND) and possibly execute arbitrary code via (1) a long user name or (2) an unknown attack related to a "special script against login."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0639">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:ichain:2.1:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:ichain:2.1</vuln:product>
      <vuln:product>cpe:/a:novell:ichain:2.1:sp1</vuln:product>
      <vuln:product>cpe:/a:novell:ichain:2.1:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0639</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:15.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105492852131747&amp;w=2" xml:lang="en">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0640">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:::express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:::express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0640</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:51.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0641">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0</vuln:product>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0.1</vuln:product>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0641</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105848106631132&amp;w=2" xml:lang="en">20030717 Bypassing ServerLock protection on Windows 2000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8222" xml:lang="en">8222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12665" xml:lang="en">serverlock-openprocess-load-module(12665)</vuln:reference>
    </vuln:references>
    <vuln:summary>WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0642">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:watchguard:serverlock:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0</vuln:product>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0.1</vuln:product>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0.2</vuln:product>
      <vuln:product>cpe:/a:watchguard:serverlock:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0642</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105848106631132&amp;w=2" xml:lang="en">20030717 Bypassing ServerLock protection on Windows 2000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8223" xml:lang="en">8223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12666" xml:lang="en">serverlock-physicalmemory-symlink(12666)</vuln:reference>
    </vuln:references>
    <vuln:summary>WatchGuard ServerLock for Windows 2000 before SL 2.0.4 allows local users to access kernel memory via a symlink attack on \Device\PhysicalMemory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0643">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22:pre10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22:pre10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0643</vuln:cve-id>
    <vuln:published-datetime>2003-07-25T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:01.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T15:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gentoo.kems.net/gentoo-x86-portage/sys-kernel/gentoo-sources/ChangeLog" xml:lang="en">http://gentoo.kems.net/gentoo-x86-portage/sys-kernel/gentoo-sources/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ultramonkey.org/bugs/cve/CAN-2003-0643.shtml" xml:lang="en">http://www.ultramonkey.org/bugs/cve/CAN-2003-0643.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ultramonkey.org/bugs/cve-patch/CAN-2003-0643.patch" xml:lang="en">http://www.ultramonkey.org/bugs/cve-patch/CAN-2003-0643.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf" xml:lang="en">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0644">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:johannes_sixt:kdbg:1.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.0</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.1</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.2</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.3</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.4</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.5</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.6</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.1.7</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.0</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.1</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.2</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.3</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.4</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.5</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.6</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.7</vuln:product>
      <vuln:product>cpe:/a:johannes_sixt:kdbg:1.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0644</vuln:cve-id>
    <vuln:published-datetime>2003-09-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:52.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T15:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.debian.org/debian-devel-changes/2003/09/msg00767.html" xml:lang="en">[debian-devel-changes] 20030909 Accepted kdbg 1.2.9-1 (i386 source)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.kde.org/?l=kde-announce&amp;m=106296509815092&amp;w=2" xml:lang="en">http://lists.kde.org/?l=kde-announce&amp;m=106296509815092&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-416.html" xml:lang="en">RHSA-2005:416</vuln:reference>
    </vuln:references>
    <vuln:summary>Kdbg 1.1.0 through 1.2.8 does not check permissions of the .kdbgrc file, which allows local users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0645">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:2.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:man:2.3.20</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:2.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0645</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106018504800341&amp;w=2" xml:lang="en">20030806 man-db[v2.4.1-]: open_cat_stream() privileged call exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-364" xml:lang="en">DSA-364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8352" xml:lang="en">8352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12848" xml:lang="en">mandb-opencatstream-gain-privileges(12848)</vuln:reference>
    </vuln:references>
    <vuln:summary>man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0646">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:damage_cleanup_server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:housecall:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:housecall:5.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:damage_cleanup_server:1.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:housecall:5.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:housecall:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0646</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:02.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionID=15274" xml:lang="en">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionID=15274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006488.html" xml:lang="en">20030711 Trend Micro ActiveX Multiple Overflows</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0647">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0647</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:02.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sn-20030730-ios-2gb-get.shtml" xml:lang="en">20030731 Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS Software</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/579324" xml:lang="en">VU#579324</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0648">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fte:fte_text_editor"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fte:fte_text_editor</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0648</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:34.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009655" xml:lang="en">1009655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009656" xml:lang="en">1009656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-472" xml:lang="en">DSA-472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/354838" xml:lang="en">VU#354838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/900964" xml:lang="en">VU#900964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10041" xml:lang="en">10041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15726" xml:lang="en">ftetexteditor-vfte-bo(15726)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0649">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xpcd:xpcd:2.08"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xpcd:xpcd:2.08</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0649</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:02.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-368" xml:lang="en">DSA-368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:053" xml:lang="en">MDKSA-2004:053</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0650">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gamespy:arcade:1.3e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gamespy:arcade:1.3e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0650</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:20.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0064.html" xml:lang="en">20030730 GameSpy Arcade Arbitrary File Writing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105958779017085&amp;w=2" xml:lang="en">20030730 GameSpy Arcade Arbitrary File Writing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gamespyarcade.com/features/versions.shtml" xml:lang="en">http://www.gamespyarcade.com/features/versions.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8309" xml:lang="en">8309</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0651">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mod_mylo:mod_mylo:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_mylo:mod_mylo:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_mylo:mod_mylo:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_mylo:mod_mylo:0.1</vuln:product>
      <vuln:product>cpe:/a:mod_mylo:mod_mylo:2.0</vuln:product>
      <vuln:product>cpe:/a:mod_mylo:mod_mylo:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0651</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:53.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-07/0355.html" xml:lang="en">20030728 Remotely exploitable overflow in mod_mylo for Apache</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8287" xml:lang="en">8287</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0652">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xtokkaetama:xtokkaetama:1.0_b6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xtokkaetama:xtokkaetama:1.0_b6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0652</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:21.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106001473329625&amp;w=2" xml:lang="en">20030803 xtokkaetama[v1.0b+]: (missed) buffer overflow exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-367" xml:lang="en">DSA-367</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in xtokkaetama allows local users to gain privileges via a long -nickname command line argument, a different vulnerability than CVE-2003-0611.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0653">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0653</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:03.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-010.txt.asc" xml:lang="en">NetBSD-SA2003-010</vuln:reference>
    </vuln:references>
    <vuln:summary>The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote attackers to cause a denial of service (kernel panic or crash) via certain OSI packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0654">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:autorespond:autorespond:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:autorespond:autorespond:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0654</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:03.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-373" xml:lang="en">DSA-373</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0655">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cdrtools:cdrtools:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cdrtools:cdrtools:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cdrtools:cdrtools:2.0</vuln:product>
      <vuln:product>cpe:/a:cdrtools:cdrtools:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0655</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:23.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105978381618095&amp;w=2" xml:lang="en">20030801 SRT2003-08-01-0126 - cdrtools local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-08-01-0126.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-08-01-0126.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi is running with privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0656">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eroaster:eroaster:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:eroaster:eroaster:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:eroaster:eroaster:2.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eroaster:eroaster:2.0.0</vuln:product>
      <vuln:product>cpe:/a:eroaster:eroaster:2.1.0</vuln:product>
      <vuln:product>cpe:/a:eroaster:eroaster:2.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0656</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:24.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252649028401&amp;w=2" xml:lang="en">20030902 GLSA:  eroaster (200309-04)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-366" xml:lang="en">DSA-366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:083" xml:lang="en">MDKSA-2003:083</vuln:reference>
    </vuln:references>
    <vuln:summary>eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0657">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0657</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:54.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-365" xml:lang="en">DSA-365</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unauthorized database actions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0658">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:caldera:openlinux_server:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:caldera:openlinux_workstation:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:caldera:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:caldera:openlinux_server:3.1.1</vuln:product>
      <vuln:product>cpe:/a:caldera:openlinux_workstation:3.1.1</vuln:product>
      <vuln:product>cpe:/a:caldera:openserver:5.0.7</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0658</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:03.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0659">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0659</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A201" name="oval:org.mitre.oval:def:201"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A340" name="oval:org.mitre.oval:def:340"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106631999907035&amp;w=2" xml:lang="en">20031016 Listbox And Combobox Control Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106632111408343&amp;w=2" xml:lang="en">20031016 Listbox And Combobox Control Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/967668" xml:lang="en">VU#967668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8827" xml:lang="en">8827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-045" xml:lang="en">MS03-045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13424" xml:lang="en">win-user32-control-bo(13424)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0660">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0660</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A185" name="oval:org.mitre.oval:def:185"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A198" name="oval:org.mitre.oval:def:198"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/838572" xml:lang="en">VU#838572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8830" xml:lang="en">8830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-041" xml:lang="en">MS03-041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13422" xml:lang="en">win-authenticode-code-execution(13422)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0661">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0661</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3483" name="oval:org.mitre.oval:def:3483"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/989932" xml:lang="en">VU#989932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-034" xml:lang="en">MS03-034</vuln:reference>
    </vuln:references>
    <vuln:summary>The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0662">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0662</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A237" name="oval:org.mitre.oval:def:237"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0015.html" xml:lang="en">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012205.html" xml:lang="en">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106632192709608&amp;w=2" xml:lang="en">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/989932" xml:lang="en">VU#989932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8833" xml:lang="en">8833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-042" xml:lang="en">MS03-042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13423" xml:lang="en">win2k-local-troubleshooter-bo(13423)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0663">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0663</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:56.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1016" name="oval:org.mitre.oval:def:1016"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/639428" xml:lang="en">VU#639428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10114" xml:lang="en">10114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15700" xml:lang="en">win2k-lsass-ldap-dos(15700)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0664">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:sr2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sr1a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:97</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:sr2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sr1a</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2001</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0664</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:57.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A188" name="oval:org.mitre.oval:def:188"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-035" xml:lang="en">MS03-035</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0665">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:97"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:access:97</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0665</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:57.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/992132" xml:lang="en">VU#992132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8536" xml:lang="en">8536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-038" xml:lang="en">MS03-038</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0666">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:wordperfect_converter"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:wordperfect_converter</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0666</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:57.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0092.html" xml:lang="en">20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106261952827573&amp;w=2" xml:lang="en">20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106279971612961&amp;w=2" xml:lang="en">20030905 Microsoft WordPerfect Document Converter Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-036" xml:lang="en">MS03-036</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0669">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0669</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4561" name="oval:org.mitre.oval:def:4561"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F47353" xml:lang="en">47353</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0670">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sustainable_softworks:ipnetmonitorx"/>
        <cpe-lang:fact-ref name="cpe:/a:sustainable_softworks:ipnetsentryx"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sustainable_softworks:ipnetmonitorx</vuln:product>
      <vuln:product>cpe:/a:sustainable_softworks:ipnetsentryx</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0670</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:05.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a080703-1.txt" xml:lang="en">A080703-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0671">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jeremy_elson:tcpflow:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:jeremy_elson:tcpflow:0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:jeremy_elson:tcpflow:0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:jeremy_elson:tcpflow:0.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jeremy_elson:tcpflow:0.10</vuln:product>
      <vuln:product>cpe:/a:jeremy_elson:tcpflow:0.11</vuln:product>
      <vuln:product>cpe:/a:jeremy_elson:tcpflow:0.12</vuln:product>
      <vuln:product>cpe:/a:jeremy_elson:tcpflow:0.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0671</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:05.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a080703-1.txt" xml:lang="en">A080703-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a080703-2.txt" xml:lang="en">A080703-2</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0672">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:leon_j_breedt:pam-pgsql:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:leon_j_breedt:pam-pgsql:0.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:leon_j_breedt:pam-pgsql:0.5.1</vuln:product>
      <vuln:product>cpe:/a:leon_j_breedt:pam-pgsql:0.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0672</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:05.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-370" xml:lang="en">DSA-370</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0676">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_directory_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_directory_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_directory_server:5.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_directory_server:5.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.0_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.1:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:iplanet_directory_server:5.0</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_directory_server:5.1</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_directory_server:5.1:sp1</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_directory_server:5.1:sp2</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.0</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.0:sp1</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.0_sp2</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.1</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.1:sp1</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.1:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0676</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:28.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106036588613929&amp;w=2" xml:lang="en">20030808 Directory Traversal in Sun iPlanet Administration Server 5.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0677">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:webns:5.0_0.038s"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:webns:5.0_0.038s</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0677</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:06.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0073.html" xml:lang="en">20030807 Cisco CSS 11000 Series DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0079.html" xml:lang="en">20030808 Re: [VulnWatch] Cisco CSS 11000 Series DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/332284" xml:lang="en">20030807 Cisco CSS 11000 Series DoS</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM Ping failure."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0678">
    <vuln:cve-id>CVE-2003-0678</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.963-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.963-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0679">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0679</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:06.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030802-01-P" xml:lang="en">20030802-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0680">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.21</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0680</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:06.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030901-01-P" xml:lang="en">20030901-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0681">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:advanced_message_server:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:advanced_message_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.8.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta16"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_pro:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_pro:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5::sh3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6:beta"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_advanced_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sendmail:advanced_message_server:1.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:advanced_message_server:1.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.8.8</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta12</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta16</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.8</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.9</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_pro:8.9.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_pro:8.9.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:0.5</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:0.7</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.1a</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.2</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc1</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc2</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.0.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.4.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5::sh3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5::x86</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6:beta</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_advanced_server:6.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:6.1</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:6.5</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:7.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:8.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:6.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:7.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0681</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3606" name="oval:org.mitre.oval:def:3606"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A595" name="oval:org.mitre.oval:def:595"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000742" xml:lang="en">CLA-2003:742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106383437615742&amp;w=2" xml:lang="en">20030917 GLSA:  sendmail (200309-13)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106398718909274&amp;w=2" xml:lang="en">20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-384" xml:lang="en">DSA-384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/108964" xml:lang="en">VU#108964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:092" xml:lang="en">MDKSA-2003:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-283.html" xml:lang="en">RHSA-2003:283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8649" xml:lang="en">8649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sendmail.org/8.12.10.html" xml:lang="en">http://www.sendmail.org/8.12.10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13216" xml:lang="en">sendmail-ruleset-parsing-bo(13216)</vuln:reference>
    </vuln:references>
    <vuln:summary>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0682">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0682</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A446" name="oval:org.mitre.oval:def:446"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000741" xml:lang="en">CLA-2003:741</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106373546332230&amp;w=2" xml:lang="en">RHSA-2003:279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381409220492&amp;w=2" xml:lang="en">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-382" xml:lang="en">DSA-382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-383" xml:lang="en">DSA-383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-280.html" xml:lang="en">RHSA-2003:280</vuln:reference>
    </vuln:references>
    <vuln:summary>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0683">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0683</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:34:58.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031004-01-P" xml:lang="en">20031004-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8921" xml:lang="en">8921</vuln:reference>
    </vuln:references>
    <vuln:summary>NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0684">
    <vuln:cve-id>CVE-2003-0684</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.980-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:00.980-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0685">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netris:netris:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:netris:netris:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:netris:netris:0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netris:netris:0.3</vuln:product>
      <vuln:product>cpe:/a:netris:netris:0.4</vuln:product>
      <vuln:product>cpe:/a:netris:netris:0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0685</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:32.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106071059430211&amp;w=2" xml:lang="en">20030812 Netris client Buffer Overflow Vulnerability.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-372" xml:lang="en">DSA-372</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Netris 0.52 and earlier, and possibly other versions, allows remote malicious Netris servers to execute arbitrary code on netris clients via a long server response.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0686">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_airlie:pam_smb:2.0_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:pam_smb:1.1.6-2::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:pam_smb:1.1.6-2::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:pam_smb:1.1.6-5::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:pam_smb:1.1.6-7::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1.1</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1.2</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1.3</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1.4</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1.5</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:1.1.6</vuln:product>
      <vuln:product>cpe:/a:dave_airlie:pam_smb:2.0_rc4</vuln:product>
      <vuln:product>cpe:/a:redhat:pam_smb:1.1.6-2::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:pam_smb:1.1.6-2::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:pam_smb:1.1.6-5::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:pam_smb:1.1.6-7::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0686</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:21.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A469" name="oval:org.mitre.oval:def:469"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000734" xml:lang="en">CLA-2003:734</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252769930090&amp;w=2" xml:lang="en">20030901 GLSA:  pam_smb (200309-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us2.samba.org/samba/ftp/pam_smb/" xml:lang="en">http://us2.samba.org/samba/ftp/pam_smb/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-374" xml:lang="en">DSA-374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/680260" xml:lang="en">VU#680260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-261.html" xml:lang="en">RHSA-2003:261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-262.html" xml:lang="en">RHSA-2003:262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-50.txt" xml:lang="en">TLSA-2003-50</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0687">
    <vuln:cve-id>CVE-2003-0687</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:09.117-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was internally assigned to a problem that was not reachable (the affected routine was not used by the software).  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0688">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.5-7::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.5-7::i386_cf"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.5-7::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.5-7::i386_doc"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.8-4::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.8-4::i386_cf"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.8-4::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:sendmail:8.12.8-4::i386_doc"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.5-7::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.5-7::i386_cf</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.5-7::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.5-7::i386_doc</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.8-4::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.8-4::i386_cf</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.8-4::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:sendmail:8.12.8-4::i386_doc</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.8</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0688</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:22.053-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A597" name="oval:org.mitre.oval:def:597"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030803-01-P" xml:lang="en">20030803-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000727" xml:lang="en">CLA-2003:727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/993452" xml:lang="en">VU#993452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:086" xml:lang="en">MDKSA-2003:086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_035_sendmail.html" xml:lang="en">SuSE-SA:2003:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-265.html" xml:lang="en">RHSA-2003:265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sendmail.org/dnsmap1.html" xml:lang="en">http://www.sendmail.org/dnsmap1.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0689">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0689</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:09.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-249.html" xml:lang="en">RHSA-2003:249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-325.html" xml:lang="en">RHSA-2003:325</vuln:reference>
    </vuln:references>
    <vuln:summary>The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0690">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5b"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0_beta</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5b</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0690</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:12.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A193" name="oval:org.mitre.oval:def:193"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html" xml:lang="en">http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" xml:lang="en">CLA-2003:747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106374551513499&amp;w=2" xml:lang="en">20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-388" xml:lang="en">DSA-388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-443" xml:lang="en">DSA-443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20030916-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20030916-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:091" xml:lang="en">MDKSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-270.html" xml:lang="en">RHSA-2003:270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-286.html" xml:lang="en">RHSA-2003:286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-287.html" xml:lang="en">RHSA-2003:287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-288.html" xml:lang="en">RHSA-2003:288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-289.html" xml:lang="en">RHSA-2003:289</vuln:reference>
    </vuln:references>
    <vuln:summary>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0691">
    <vuln:cve-id>CVE-2003-0691</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:09.680-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not associated with any specific security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0692">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5b"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0_beta</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5b</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0692</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:13.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A215" name="oval:org.mitre.oval:def:215"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html" xml:lang="en">http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" xml:lang="en">CLA-2003:747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106374551513499&amp;w=2" xml:lang="en">20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-388" xml:lang="en">DSA-388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20030916-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20030916-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:091" xml:lang="en">MDKSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-270.html" xml:lang="en">RHSA-2003:270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-288.html" xml:lang="en">RHSA-2003:288</vuln:reference>
    </vuln:references>
    <vuln:summary>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0693">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0693</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:22.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2719" name="oval:org.mitre.oval:def:2719"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A447" name="oval:org.mitre.oval:def:447"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010103.html" xml:lang="en">20030915 new ssh exploit?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010135.html" xml:lang="en">20030915 openssh remote exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010146.html" xml:lang="en">20030916 The lowdown on SSH vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106373247528528&amp;w=2" xml:lang="en">20030916 OpenSSH Buffer Management Bug Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106373546332230&amp;w=2" xml:lang="en">RHSA-2003:279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106374466212309&amp;w=2" xml:lang="en">20030916 [slackware-security]  OpenSSH Security Advisory (SSA:2003-259-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381396120332&amp;w=2" xml:lang="en">2003-0033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381409220492&amp;w=2" xml:lang="en">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000620.1-1" xml:lang="en">1000620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-24.html" xml:lang="en">CA-2003-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-382" xml:lang="en">DSA-382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-383" xml:lang="en">DSA-383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/333628" xml:lang="en">VU#333628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:090" xml:lang="en">MDKSA-2003:090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssh.com/txt/buffer.adv" xml:lang="en">http://www.openssh.com/txt/buffer.adv</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-280.html" xml:lang="en">RHSA-2003:280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13191" xml:lang="en">openssh-packet-bo(13191)</vuln:reference>
    </vuln:references>
    <vuln:summary>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0694">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:advanced_message_server:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:advanced_message_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.8.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta16"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_pro:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_pro:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk8_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk4_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk4_bl21"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk5_bl23"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk2_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release_p38"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:release_p42"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release_p32"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release_p20"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release_p17"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:release_p6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:release_p14"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release_p5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5::sh3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6:beta"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_advanced_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_server:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_workstation:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sendmail:advanced_message_server:1.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:advanced_message_server:1.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.8.8</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta12</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta16</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.8</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.9</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_pro:8.9.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_pro:8.9.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk8_bl22</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk4_bl22</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk4_bl21</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk5_bl23</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk2_bl22</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release_p38</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:release_p42</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release_p32</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release_p20</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release_p17</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:release_p6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:release_p14</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release_p5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:0.5</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:0.7</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.1a</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.2</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc1</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc2</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.0.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.4.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5::sh3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5::x86</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6:beta</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_advanced_server:6.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:6.1</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:6.5</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:7.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_server:8.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:6.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:7.0</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_workstation:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0694</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2975" name="oval:org.mitre.oval:def:2975"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A572" name="oval:org.mitre.oval:def:572"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A603" name="oval:org.mitre.oval:def:603"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt" xml:lang="en">SCOSA-2004.11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.html" xml:lang="en">20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.html" xml:lang="en">20030917 Zalewski Advisory - Sendmail 8.12.9 prescan bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000742" xml:lang="en">CLA-2003:742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381604923204&amp;w=2" xml:lang="en">20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106382859407683&amp;w=2" xml:lang="en">20030917 [slackware-security]  Sendmail vulnerabilities fixed (SSA:2003-260-02)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106383437615742&amp;w=2" xml:lang="en">20030917 GLSA:  sendmail (200309-13)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106398718909274&amp;w=2" xml:lang="en">20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-25.html" xml:lang="en">CA-2003-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-384" xml:lang="en">DSA-384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/784980" xml:lang="en">VU#784980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:092" xml:lang="en">MDKSA-2003:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-283.html" xml:lang="en">RHSA-2003:283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-284.html" xml:lang="en">RHSA-2003:284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sendmail.org/8.12.10.html" xml:lang="en">http://www.sendmail.org/8.12.10.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0695">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0695</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:22.490-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A452" name="oval:org.mitre.oval:def:452"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000741" xml:lang="en">CLA-2003:741</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106373546332230&amp;w=2" xml:lang="en">RHSA-2003:279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381396120332&amp;w=2" xml:lang="en">2003-0033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381409220492&amp;w=2" xml:lang="en">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106382542403716&amp;w=2" xml:lang="en">20030917 [slackware-security]  OpenSSH updated again (SSA:2003-260-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=openbsd-security-announce&amp;m=106375582924840" xml:lang="en">http://marc.info/?l=openbsd-security-announce&amp;m=106375582924840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-382" xml:lang="en">DSA-382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-383" xml:lang="en">DSA-383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:090" xml:lang="en">MDKSA-2003:090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssh.com/txt/buffer.adv" xml:lang="en">http://www.openssh.com/txt/buffer.adv</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-280.html" xml:lang="en">RHSA-2003:280</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0696">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0696</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8738" xml:lang="en">8738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13328" xml:lang="en">aix-sendmail-getipnodebyname-dos(13328)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://techsupport.services.ibm.com/server/pseries.subscriptionSvcs?mode=7&amp;heading=AIX51&amp;topic=SECURITY&amp;month=200310&amp;label=getipnodebyname%28%29+API+does+not+close+sockets.&amp;date=20031001&amp;bulletin=datafile150755&amp;embed=true" xml:lang="en">https://techsupport.services.ibm.com/server/pseries.subscriptionSvcs?mode=7&amp;heading=AIX51&amp;topic=SECURITY&amp;month=200310&amp;label=getipnodebyname%28%29+API+does+not+close+sockets.&amp;date=20031001&amp;bulletin=datafile150755&amp;embed=true</vuln:reference>
    </vuln:references>
    <vuln:summary>The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0697">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0697</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:12.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1605.1" xml:lang="en">http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1605.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY45250&amp;apar=only" xml:lang="en">IY45250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY45344&amp;apar=only" xml:lang="en">IY45344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY46256&amp;apar=only" xml:lang="en">IY46256</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0698">
    <vuln:cve-id>CVE-2003-0698</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:13.070-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0743.  Reason: This candidate is a duplicate of CVE-2003-0743.  Notes: All CVE users should reference CVE-2003-0743 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0699">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0699</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:13.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A387" name="oval:org.mitre.oval:def:387"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-198.html" xml:lang="en">RHSA-2003:198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-239.html" xml:lang="en">RHSA-2003:239</vuln:reference>
    </vuln:references>
    <vuln:summary>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0700">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:kernel:2.4.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0700</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:13.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A401" name="oval:org.mitre.oval:def:401"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-238.html" xml:lang="en">RHSA-2003:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-044.html" xml:lang="en">RHSA-2004:044</vuln:reference>
    </vuln:references>
    <vuln:summary>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0701">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0::windows_server_2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0::windows_server_2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0701</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:32:58.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106148101210479&amp;w=2" xml:lang="en">20030820 [SNS Advisory No.68] Internet Explorer Object Type Buffer Overflow in Double-Byte Character Set Environment</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/334928" xml:lang="en">VU#334928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032" xml:lang="en">MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12970" xml:lang="en">ie-dbcs-object-bo(12970)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0702">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_server_sensor:7.0:xpu20.16"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_server_sensor:7.0:xpu20.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:iss:realsecure_server_sensor:7.0:xpu20.16</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_server_sensor:7.0:xpu20.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0702</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106278164225389&amp;w=2" xml:lang="en">20030905 ISS Server Sensor Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.enteredge.com/research/CAN-2003-0702.asp" xml:lang="en">http://www.enteredge.com/research/CAN-2003-0702.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13088" xml:lang="en">realsecure-isapi-dos(13088)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server (IIS) via a certain URL through SSL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0703">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kismac:kismac:0.05d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kismac:kismac:0.05d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0703</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a082203-1.txt" xml:lang="en">A082203-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8497" xml:lang="en">8497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13007" xml:lang="en">kismac-driverkext-load-modules(13007)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13008" xml:lang="en">kismac-exchangekernel-kernel-overwrite(13008)</vuln:reference>
    </vuln:references>
    <vuln:summary>KisMAC before 0.05d trusts user-supplied variables to load arbitrary kernels or kernel modules, which allows local users to gain privileges via the $DRIVER_KEXT environment variable as used in (1) viha_driver.sh, (2) macjack_load.sh, or (3) airojack_load.sh, or (4) via "similar techniques" using exchangeKernel.sh.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0704">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kismac:kismac:0.05d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kismac:kismac:0.05d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0704</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a082203-1.txt" xml:lang="en">A082203-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8497" xml:lang="en">8497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13006" xml:lang="en">kismac-driverkext-modify-ownership(13006)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13009" xml:lang="en">kismac-setuid-modify-ownership(13009)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13010" xml:lang="en">kismac-viha-gain-privileges(13010)</vuln:reference>
    </vuln:references>
    <vuln:summary>KisMAC before 0.05d trusts user-supplied variables when chown'ing files or directories, which allows local users to gain privileges via the $DRIVER_KEXT environment variable in (1) viha_driver.sh, (2) macjack_load.sh, (3) airojack_load.sh, (4) setuid_enable.sh, (5) setuid_disable.sh, and using a "similar technique" for (6) viha_prep.sh and (7) viha_unprep.sh.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0705">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicolas_boullis:mah-jong:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicolas_boullis:mah-jong:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0705</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:13.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-378" xml:lang="en">DSA-378</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0706">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicolas_boullis:mah-jong:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicolas_boullis:mah-jong:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0706</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:13.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-378" xml:lang="en">DSA-378</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0707">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tomi_manninen:linuxnode:0.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tomi_manninen:linuxnode:0.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0707</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:02.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-375" xml:lang="en">DSA-375</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0708">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tomi_manninen:linuxnode:0.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tomi_manninen:linuxnode:0.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0708</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:02.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-375" xml:lang="en">DSA-375</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0709">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:whois:whois:4.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:whois:whois:4.6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:whois:whois:4.5.7</vuln:product>
      <vuln:product>cpe:/a:whois:whois:4.6.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0709</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:14.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zone-h.org/en/advisories/read/id=2925/" xml:lang="en">http://www.zone-h.org/en/advisories/read/id=2925/</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0711">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0711</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A217" name="oval:org.mitre.oval:def:217"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3685" name="oval:org.mitre.oval:def:3685"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3889" name="oval:org.mitre.oval:def:3889"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4706" name="oval:org.mitre.oval:def:4706"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106631908105696&amp;w=2" xml:lang="en">20031016 Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106632194809632&amp;w=2" xml:lang="en">20031016 Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/467036" xml:lang="en">VU#467036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/ms-pchealth.txt" xml:lang="en">http://www.ngssoftware.com/advisories/ms-pchealth.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8828" xml:lang="en">8828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-044" xml:lang="en">MS03-044</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0712">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0712</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:00.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106631918405915&amp;w=2" xml:lang="en">20031016 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/435444" xml:lang="en">VU#435444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8832" xml:lang="en">8832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047" xml:lang="en">MS03-047</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0714">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0714</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:01.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106682909006586&amp;w=2" xml:lang="en">20031022 MS03-046 Microsoft Exchange 2000 Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/422156" xml:lang="en">VU#422156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8838" xml:lang="en">8838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046" xml:lang="en">MS03-046</vuln:reference>
    </vuln:references>
    <vuln:summary>The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0715">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0715</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1202" name="oval:org.mitre.oval:def:1202"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1813" name="oval:org.mitre.oval:def:1813"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A20" name="oval:org.mitre.oval:def:20"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A264" name="oval:org.mitre.oval:def:264"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4224" name="oval:org.mitre.oval:def:4224"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106322856608909&amp;w=2" xml:lang="en">20030910 EEYE: Microsoft RPC Heap Corruption Vulnerability - Part II</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-23.html" xml:lang="en">CA-2003-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/483492" xml:lang="en">VU#483492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039" xml:lang="en">MS03-039</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0717">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0717</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A213" name="oval:org.mitre.oval:def:213"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A268" name="oval:org.mitre.oval:def:268"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106666713812158&amp;w=2" xml:lang="en">20031018 Proof of concept for Windows Messenger Service overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106632188709562&amp;w=2" xml:lang="en">20031016 MS03-043 Popup Messenger Servce buffer-overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-27.html" xml:lang="en">CA-2003-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/575892" xml:lang="en">VU#575892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8826" xml:lang="en">8826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-043" xml:lang="en">MS03-043</vuln:reference>
    </vuln:references>
    <vuln:summary>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0718">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_services:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_services:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0718</vuln:cve-id>
    <vuln:published-datetime>2004-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1330" name="oval:org.mitre.oval:def:1330"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1427" name="oval:org.mitre.oval:def:1427"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4767" name="oval:org.mitre.oval:def:4767"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109762641822064&amp;w=2" xml:lang="en">20041012 Microsoft IIS 5.x/6.0 WebDAV (XML parser) attribute blowup DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-030" xml:lang="en">MS04-030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/17645" xml:lang="en">iis-webdav-xml-attribute-dos(17645)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/17656" xml:lang="en">iis-ms04030-patch(17656)</vuln:reference>
    </vuln:references>
    <vuln:summary>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0719">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:netmeeting"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:netmeeting</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0719</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:05.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1093" name="oval:org.mitre.oval:def:1093"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A889" name="oval:org.mitre.oval:def:889"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A903" name="oval:org.mitre.oval:def:903"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A951" name="oval:org.mitre.oval:def:951"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/586540" xml:lang="en">VU#586540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/361836" xml:lang="en">20040430 A technical description of the SSL PCT vulnerability (CVE-2003-0719)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/168" xml:lang="en">20040413 Microsoft SSL Library Remote Compromise Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0720">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:3.98"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.20"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.21"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.30"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.33"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.44"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.50"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.52"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.53"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.56"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:pine:3.98</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.0.2</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.0.4</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.10</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.20</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.21</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.30</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.33</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.44</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.50</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.52</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.53</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.56</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0720</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:22.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A499" name="oval:org.mitre.oval:def:499"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0099.html" xml:lang="en">20030910 iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106322571805153&amp;w=2" xml:lang="en">20030910 iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106329356702508&amp;w=2" xml:lang="en">20030911 [slackware-security]  security issues in pine (SSA:2003-253-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/09.10.03.txt" xml:lang="en">http://www.idefense.com/advisory/09.10.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-273.html" xml:lang="en">RHSA-2003:273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-274.html" xml:lang="en">RHSA-2003:274</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0721">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:3.98"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.20"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.21"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.30"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.33"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.44"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.50"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.52"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.53"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.56"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:pine:3.98</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.0.2</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.0.4</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.10</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.20</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.21</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.30</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.33</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.44</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.50</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.52</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.53</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pine:4.56</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0721</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:22.693-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A503" name="oval:org.mitre.oval:def:503"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009850.html" xml:lang="en">20030911 Pine: .procmailrc rule against integer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106329356702508&amp;w=2" xml:lang="en">20030911 [slackware-security]  security issues in pine (SSA:2003-253-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106367213400313&amp;w=2" xml:lang="en">20030915 remote Pine &lt;= 4.56 exploit fully automatic</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/09.10.03.txt" xml:lang="en">20030910 Two Exploitable Overflows in PINE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-273.html" xml:lang="en">RHSA-2003:273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-274.html" xml:lang="en">RHSA-2003:274</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0722">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0722</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:13.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1273" name="oval:org.mitre.oval:def:1273"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0115.html" xml:lang="en">20030918 Solaris SADMIND Exploitation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106391959014331&amp;w=2" xml:lang="en">20030918 Solaris SADMIND Exploitation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56740-1&amp;searchclause=security" xml:lang="en">56740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-148.shtml" xml:lang="en">N-148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/09.16.03.txt" xml:lang="en">http://www.idefense.com/advisory/09.16.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/41870" xml:lang="en">VU#41870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8615" xml:lang="en">8615</vuln:reference>
    </vuln:references>
    <vuln:summary>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0723">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gkrellm:gkrellm:2.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gkrellm:gkrellm:2.1.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gkrellm:gkrellm:2.1.7</vuln:product>
      <vuln:product>cpe:/a:gkrellm:gkrellm:2.1.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0723</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:15.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:087" xml:lang="en">MDKSA-2003:087</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0724">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk4_bl21"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk5_bl23"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk2_bl22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk4_bl21</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk5_bl23</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk2_bl22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0724</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:05.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5736" xml:lang="en">SSRT3588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8492" xml:lang="en">8492</vuln:reference>
    </vuln:references>
    <vuln:summary>ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0725">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_server:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_server:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_server:9.0.2.794"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:8.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realserver:g2_1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:helix_universal_server:8.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:helix_universal_server:9.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:helix_universal_server:9.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:helix_universal_server:9.0.2.794</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:7.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:7.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:7.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:8.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:8.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:8.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:8.0_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realserver:g2_1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0725</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:05.313-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0087.html" xml:lang="en">20030825 New Bug in RealServer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html" xml:lang="en">http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/934932" xml:lang="en">VU#934932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8476" xml:lang="en">8476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.service.real.com/help/faq/security/rootexploit082203.html" xml:lang="en">http://www.service.real.com/help/faq/security/rootexploit082203.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0726">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_desktop_manager"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.10.505:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.818"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.830"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.841"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.853"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_desktop_manager</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.10.505:gold</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.818</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.830</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.841</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.853</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0726</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007532" xml:lang="en">1007532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html" xml:lang="en">http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/335293" xml:lang="en">20030827 RealOne Player Allows Cross Zone and Domain Access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8453" xml:lang="en">8453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.service.real.com/help/faq/security/securityupdate_august2003.html" xml:lang="en">http://www.service.real.com/help/faq/security/securityupdate_august2003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13028" xml:lang="en">realone-smil-execute-code(13028)</vuln:reference>
    </vuln:references>
    <vuln:summary>RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0727">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0727</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-09-27T21:29:00.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003Alert58.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003Alert58.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/42780/" xml:lang="en">42780</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0728">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:horde:horde:2.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:horde:horde:2.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0728</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:56.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106081310531567&amp;w=2" xml:lang="en">20030813 PCL-0001: Remote Vulnerability in HORDE MTA &lt; 2.2.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252836330987&amp;w=2" xml:lang="en">20030901 GLSA:  horde (200309-02)</vuln:reference>
    </vuln:references>
    <vuln:summary>Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0729">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tellurian:tftpdnt:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tellurian:tftpdnt:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tellurian:tftpdnt:1.8</vuln:product>
      <vuln:product>cpe:/a:tellurian:tftpdnt:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0729</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:57.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0091.html" xml:lang="en">20030901 Security Vulnerability in Tellurian TftpdNT (Long Filename)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252411425545&amp;w=2" xml:lang="en">20030901 Security Vulnerability in Tellurian TftpdNT (Long Filename)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/5RP0M1PAUM.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/5RP0M1PAUM.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0730">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0730</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:58.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-015.txt.asc" xml:lang="en">NetBSD-SA2003-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031101-01-U.asc" xml:lang="en">20031101-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" xml:lang="en">CLA-2004:821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106229335312429&amp;w=2" xml:lang="en">20030830 Multiple integer overflows in XFree86 (local/remote)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1" xml:lang="en">102803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-380" xml:lang="en">DSA-380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:089" xml:lang="en">MDKSA-2003:089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-286.html" xml:lang="en">RHSA-2003:286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-287.html" xml:lang="en">RHSA-2003:287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-288.html" xml:lang="en">RHSA-2003:288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-289.html" xml:lang="en">RHSA-2003:289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8514" xml:lang="en">8514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0589" xml:lang="en">ADV-2007-0589</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0731">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager_essentials:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager_essentials:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager_essentials:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:1st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:2nd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:3rd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:4th"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:5th"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager:1.1</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager_essentials:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager_essentials:2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager_essentials:2.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:1st</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:2nd</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:3rd</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:4th</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:5th</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0731</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:19.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml" xml:lang="en">20030813 CiscoWorks Application Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/333028" xml:lang="en">20030813 Portcullis Security Advisory: CiscoWorks 2000 Privilege Escalation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0732">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager_essentials:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager_essentials:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:resource_manager_essentials:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:1st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:2nd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:3rd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:4th"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ciscoworks_cd1:5th"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager:1.1</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager_essentials:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager_essentials:2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:resource_manager_essentials:2.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:1st</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:2nd</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:3rd</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:4th</vuln:product>
      <vuln:product>cpe:/o:cisco:ciscoworks_cd1:5th</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0732</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:06.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml" xml:lang="en">20030813 CiscoWorks Application Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/333028" xml:lang="en">20030813 Portcullis Security Advisory: CiscoWorks 2000 Privilege Escalation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0733">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:liquid_data:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_integration:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_integration:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:liquid_data:1.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_integration:2.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_integration:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:5.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0733</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:06.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8357" xml:lang="en">8357</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other vulnerabilities in the WebLogic Server console application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0734">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:padl_software:pam_ldap:162"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:padl_software:pam_ldap:162</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0734</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:19.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:088" xml:lang="en">MDKSA-2003:088</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0735">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpwebsite:phpwebsite:0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpwebsite:phpwebsite:0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0735</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:36:59.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2" xml:lang="en">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2" xml:lang="en">20030902 GLSA:  phpwebsite (200309-03)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/925166" xml:lang="en">VU#925166</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0736">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpwebsite:phpwebsite:0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpwebsite:phpwebsite:0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0736</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:01.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2" xml:lang="en">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2" xml:lang="en">20030902 GLSA:  phpwebsite (200309-03)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/664422" xml:lang="en">VU#664422</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0737">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpwebsite:phpwebsite:0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpwebsite:phpwebsite:0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0737</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:02.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2" xml:lang="en">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2" xml:lang="en">20030902 GLSA:  phpwebsite (200309-03)</vuln:reference>
    </vuln:references>
    <vuln:summary>The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0738">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpwebsite:phpwebsite:0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpwebsite:phpwebsite:0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0738</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:03.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2" xml:lang="en">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2" xml:lang="en">20030902 GLSA:  phpwebsite (200309-03)</vuln:reference>
    </vuln:references>
    <vuln:summary>The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0739">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0.1_build_5289"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:4.0.1_build_5289</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0739</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:04.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106029217115023&amp;w=2" xml:lang="en">20030807 VMware Workstation 4.0.1 (for Linux systems) vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1106" xml:lang="en">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1106</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0740">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.21a"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.21c"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stunnel:stunnel:3.3</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.4a</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.7</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.8</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.9</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.10</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.11</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.12</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.13</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.14</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.15</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.16</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.17</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.18</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.19</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.20</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.21</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.21a</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.21b</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.21c</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.22</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.24</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0740</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:06.113-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000736" xml:lang="en">CLA-2003:736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106260760211958&amp;w=2" xml:lang="en">20030903 Stunnel-3.x Daemon Hijacking</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:108" xml:lang="en">MDKSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-297.html" xml:lang="en">RHSA-2003:297</vuln:reference>
    </vuln:references>
    <vuln:summary>Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0741">
    <vuln:cve-id>CVE-2003-0741</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:00.993-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.010-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0742">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0.5</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0742</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:20.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0743">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.30"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.31"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.33"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.34"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.35"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:3.36"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.0</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.3</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.3.1</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.3.2</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.11</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.12</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.13</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.14</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.15</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.16</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.17</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.18</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.19</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.20</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.21</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.22</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.30</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.31</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.32</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.33</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.34</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.35</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:3.36</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.10</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0743</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:07.410-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000735" xml:lang="en">CLA-2003:735</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106252015820395&amp;w=2" xml:lang="en">20030901 exim remote heap overflow, probably not exploitable</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://marc.info/?l=vuln-dev&amp;m=106264740820334&amp;w=2" xml:lang="en">20030903 Re: exim remote heap overflow, probably not exploitable</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog" xml:lang="en">http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog" xml:lang="en">http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-376" xml:lang="en">DSA-376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.exim.org/pipermail/exim-announce/2003q3/000094.html" xml:lang="en">http://www.exim.org/pipermail/exim-announce/2003q3/000094.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.html" xml:lang="en">[Exim] 20030814 Minor security bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.html" xml:lang="en">[Exim] 20030815 Minor security bug</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0744">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.19"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.20"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.21"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.22"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.23"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.24"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.25"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.26"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.27"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.29"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.30"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.31"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.35"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.36"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.37"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.38"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.39"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.40"/>
        <cpe-lang:fact-ref name="cpe:/a:leafnode:leafnode:1.9.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.19</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.20</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.21</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.22</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.23</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.24</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.25</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.26</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.27</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.29</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.30</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.31</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.35</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.36</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.37</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.38</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.39</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.40</vuln:product>
      <vuln:product>cpe:/a:leafnode:leafnode:1.9.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0744</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:08.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/" xml:lang="en">20030903 leafnode 1.9.3 - 1.9.41 security announcement SA-2003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://leafnode.sourceforge.net/leafnode-SA-2003-01.txt" xml:lang="en">http://leafnode.sourceforge.net/leafnode-SA-2003-01.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106270038210736&amp;w=2" xml:lang="en">20030904 leafnode 1.9.3 - 1.9.41 security announcement SA-2003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8541" xml:lang="en">8541</vuln:reference>
    </vuln:references>
    <vuln:summary>The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0745">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:castle_rock_computing:snmpc:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:castle_rock_computing:snmpc:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:castle_rock_computing:snmpc:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:castle_rock_computing:snmpc:6.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:castle_rock_computing:snmpc:5.1</vuln:product>
      <vuln:product>cpe:/a:castle_rock_computing:snmpc:6.0</vuln:product>
      <vuln:product>cpe:/a:castle_rock_computing:snmpc:6.0.5</vuln:product>
      <vuln:product>cpe:/a:castle_rock_computing:snmpc:6.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0745</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:20.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-08/0340.html" xml:lang="en">20030825 SNMPc v5 and v6 remote vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0746">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0746</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:08.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030902-01-P" xml:lang="en">20030902-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q3/0042.html" xml:lang="en">HPSBUX0308-274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/377804" xml:lang="en">VU#377804</vuln:reference>
    </vuln:references>
    <vuln:summary>Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerabilities CVE-2003-0352 or CVE-2003-0605, such as the Blaster/MSblast/LovSAN worm.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0747">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:4620.2.0.323011"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:internet_transaction_server:4620.2.0.323011</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0747</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" xml:lang="en">20030830 SAP Internet Transaction Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8515" xml:lang="en">8515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13063" xml:lang="en">its-wgatedll-information-disclosure(13063)</vuln:reference>
    </vuln:references>
    <vuln:summary>wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~language, (4) ~theme, or (5) ~template, which leaks the information in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0748">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:4620.2.0.323011"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:internet_transaction_server:4620.2.0.323011</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0748</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.713-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" xml:lang="en">20030830 SAP Internet Transaction Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8516" xml:lang="en">8516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13066" xml:lang="en">its-wgatedll-directory-traversal(13066)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0749">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:4620.2.0.323011"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:internet_transaction_server:4620.2.0.323011</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0749</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:09.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" xml:lang="en">20030830 SAP Internet Transaction Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8517" xml:lang="en">8517</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0750">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:py-membres:py-membres:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:py-membres:py-membres:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:py-membres:py-membres:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:py-membres:py-membres:4.0</vuln:product>
      <vuln:product>cpe:/a:py-membres:py-membres:4.1</vuln:product>
      <vuln:product>cpe:/a:py-membres:py-membres:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0750</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:21.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0089.html" xml:lang="en">20030826 [PHP] PY-Membres 4.2 : Admin Access, SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:summary>secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0751">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:py-membres:py-membres:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:py-membres:py-membres:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:py-membres:py-membres:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:py-membres:py-membres:4.0</vuln:product>
      <vuln:product>cpe:/a:py-membres:py-membres:4.1</vuln:product>
      <vuln:product>cpe:/a:py-membres:py-membres:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0751</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:21.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0089.html" xml:lang="en">20030826 [PHP] PY-Membres 4.2 : Admin Access, SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0752">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:attila-php.net:attilaphp:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:attila-php.net:attilaphp:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0752</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:09.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0090.html" xml:lang="en">20030826 [PHP] AttilaPHP 3.0 : User/Admin Access</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0753">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:newsphp:newsphp:216"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:newsphp:newsphp:216</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0753</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:21.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html" xml:lang="en">20030824 newsPHP file inclusion &amp; bad login validation</vuln:reference>
    </vuln:references>
    <vuln:summary>nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0754">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:newsphp:newsphp:216"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:newsphp:newsphp:216</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0754</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:21.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html" xml:lang="en">20030824 newsPHP file inclusion &amp; bad login validation</vuln:reference>
    </vuln:references>
    <vuln:summary>nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0755">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gtkftpd:gtkftp:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gtkftpd:gtkftp:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gtkftpd:gtkftp:1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gtkftpd:gtkftp:1.0.2</vuln:product>
      <vuln:product>cpe:/a:gtkftpd:gtkftp:1.0.3</vuln:product>
      <vuln:product>cpe:/a:gtkftpd:gtkftp:1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0755</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:21.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vuln-dev/2003-q3/0101.html" xml:lang="en">20030826 gtkftpd[v1.0.4(and below)]: remote root buffer overflow exploit.</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0756">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sitebuilder:sitebuilder:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sitebuilder:sitebuilder:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0756</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:21.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-09/0011.html" xml:lang="en">20030831 Directory Traversal in SITEBUILDER - v1.4</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0757">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.0</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0757</vuln:cve-id>
    <vuln:published-datetime>2003-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:10.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-09/0018.html" xml:lang="en">20030902 IRM 007: The IP addresses of Check Point Firewall-1 internal interfaces may be enumerated using SecuRemote</vuln:reference>
    </vuln:references>
    <vuln:summary>Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0758">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.2::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.2::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0758</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0114.html" xml:lang="en">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106389919618721&amp;w=2" xml:lang="en">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-154.shtml" xml:lang="en">N-154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8552" xml:lang="en">8552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13218" xml:lang="en">ibm-db2-db2dart-bo(13218)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0759">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.2::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.2::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0759</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:11.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt" xml:lang="en">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0114.html" xml:lang="en">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106389919618721&amp;w=2" xml:lang="en">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-154.shtml" xml:lang="en">N-154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8553" xml:lang="en">8553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-3.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/aparlib.d2w/display_apar_details?aparno=IY47653" xml:lang="en">IY47653</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0760">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:optisoft:blubster:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:optisoft:blubster:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0760</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/5RP0N15AUC.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/5RP0N15AUC.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8482" xml:lang="en">8482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13012" xml:lang="en">blubster-port701-dos(13012)</vuln:reference>
    </vuln:references>
    <vuln:summary>Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0761">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digium:asterisk:1.2.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0761</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:11.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a090403-1.txt" xml:lang="en">A090403-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before August 15, 2003, allows remote attackers to execute arbitrary code via certain (1) MESSAGE or (2) INFO requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0762">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:foxweb:foxweb:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:foxweb:foxweb:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0762</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:23.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0096.html" xml:lang="en">20030905 [SCAN Associates Sdn Bhd Security Advisory] Foxweb 2.5 bufferoverflow in CGI and ISAPI extension</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0763">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squished_mosquito:escapade"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squished_mosquito:escapade</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0763</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:12.660-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106312344631197&amp;w=2" xml:lang="en">20030909 Escapade Scripting Engine XSS Vulnerability and Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0764">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squished_mosquito:escapade"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squished_mosquito:escapade</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0764</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:13.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106312344631197&amp;w=2" xml:lang="en">20030909 Escapade Scripting Engine XSS Vulnerability and Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:summary>Escapade Scripting Engine (ESP) allows remote attackers to obtain sensitive path information via a malformed request, which leaks the information in an error message, as demonstrated using the PAGE parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0765">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:2.81"/>
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:2.91"/>
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nullsoft:winamp:2.81</vuln:product>
      <vuln:product>cpe:/a:nullsoft:winamp:2.91</vuln:product>
      <vuln:product>cpe:/a:nullsoft:winamp:3.0</vuln:product>
      <vuln:product>cpe:/a:nullsoft:winamp:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0765</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:14.740-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106305643432112&amp;w=2" xml:lang="en">20030908 Winamp 2.91 lets code execution through MIDI files</vuln:reference>
    </vuln:references>
    <vuln:summary>The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0766">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ftp_desktop:ftp_desktop:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ftp_desktop:ftp_desktop:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0766</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-04-28T21:59:00.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106305502230604&amp;w=2" xml:lang="en">20030908 Multiple Heap Overflows in FTP Desktop</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER command, or (3) a long response to a PASS command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0767">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_dedicated_server:0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_dedicated_server:0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_dedicated_server:0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_dedicated_server:0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_dedicated_server:0.30a"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gamespy:roger_wilco_dedicated_server:0.26</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_dedicated_server:0.27</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_dedicated_server:0.28</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_dedicated_server:0.29</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_dedicated_server:0.30a</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.1</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.2</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.3</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.4</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.5</vuln:product>
      <vuln:product>cpe:/a:gamespy:roger_wilco_graphical_server:1.4.1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0767</vuln:cve-id>
    <vuln:published-datetime>2003-09-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:17.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106304902323758&amp;w=2" xml:lang="en">20030908 Rogerwilco: server's buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client request with a large length value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0768">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:asp.net:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:asp.net:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0768</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:18.567-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106304326916062&amp;w=2" xml:lang="en">20030908 Advisory: Incorrect Handling of XSS Protection in ASP.Net</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0769">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3777"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3799"/>
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:2003a_build3800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3777</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3799</vuln:product>
      <vuln:product>cpe:/a:mirabilis:icq:2003a_build3800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0769</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:24.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0770">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ikonboard.com:ikonboard:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ikonboard.com:ikonboard:3.1.2a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ikonboard.com:ikonboard:3.1.1</vuln:product>
      <vuln:product>cpe:/a:ikonboard.com:ikonboard:3.1.2a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0770</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:19.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381136115972&amp;w=2" xml:lang="en">20030917 Exploit: IkonBoard 3.1.1/3.1.2a arbitrary command execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317234" xml:lang="en">20030401 IkonBoard v3.1.1: arbitrary command execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/336598" xml:lang="en">20030908 IkonBoard 3.1.2a arbitrary command execution</vuln:reference>
    </vuln:references>
    <vuln:summary>FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0771">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache_gallery:apache_gallery:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache_gallery:apache_gallery:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache_gallery:apache_gallery:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache_gallery:apache_gallery:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache_gallery:apache_gallery:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache_gallery:apache_gallery:0.4</vuln:product>
      <vuln:product>cpe:/a:apache_gallery:apache_gallery:0.4.1</vuln:product>
      <vuln:product>cpe:/a:apache_gallery:apache_gallery:0.5</vuln:product>
      <vuln:product>cpe:/a:apache_gallery:apache_gallery:0.5.1</vuln:product>
      <vuln:product>cpe:/a:apache_gallery:apache_gallery:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0771</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:21.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106304236914921&amp;w=2" xml:lang="en">20030907 Apache::Gallery local webserver compromise, privilege escalation</vuln:reference>
    </vuln:references>
    <vuln:summary>Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0772">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ipswitch:ws_ftp_server:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:progress:ipswitch_ws_ftp_server:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ipswitch:ws_ftp_server:4.01</vuln:product>
      <vuln:product>cpe:/a:progress:ipswitch_ws_ftp_server:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0772</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-08-13T10:39:50.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106288825902868&amp;w=2" xml:lang="en">20030906 Remote and Local Vulnerabilities In WS_FTP Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/219140" xml:lang="en">VU#219140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/792284" xml:lang="en">VU#792284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8542" xml:lang="en">8542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13119" xml:lang="en">wsftp-ftp-command-bo(13119)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0773">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane-backend:1.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sane:sane:1.0.0</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.3</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.4</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.5</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.6</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.8</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.9</vuln:product>
      <vuln:product>cpe:/a:sane:sane-backend:1.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0773</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-08-23T00:29:24.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" xml:lang="en">CSSA-2004-005.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-379" xml:lang="en">DSA-379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" xml:lang="en">MDKSA-2003:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_046_sane.html" xml:lang="en">SuSE-SA:2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-278.html" xml:lang="en">RHSA-2003:278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-285.html" xml:lang="en">RHSA-2003:285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8593" xml:lang="en">8593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8595" xml:lang="en">8595</vuln:reference>
    </vuln:references>
    <vuln:summary>saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0774">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane-backend:1.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sane:sane:1.0.0</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.3</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.4</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.5</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.6</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.8</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.9</vuln:product>
      <vuln:product>cpe:/a:sane:sane-backend:1.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0774</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" xml:lang="en">CSSA-2004-005.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-379" xml:lang="en">DSA-379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" xml:lang="en">MDKSA-2003:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_046_sane.html" xml:lang="en">SuSE-SA:2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-278.html" xml:lang="en">RHSA-2003:278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-285.html" xml:lang="en">RHSA-2003:285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8593" xml:lang="en">8593</vuln:reference>
    </vuln:references>
    <vuln:summary>saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0775">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane-backend:1.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sane:sane:1.0.0</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.3</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.4</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.5</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.6</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.8</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.9</vuln:product>
      <vuln:product>cpe:/a:sane:sane-backend:1.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0775</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" xml:lang="en">CSSA-2004-005.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-379" xml:lang="en">DSA-379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" xml:lang="en">MDKSA-2003:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_046_sane.html" xml:lang="en">SuSE-SA:2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-278.html" xml:lang="en">RHSA-2003:278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-285.html" xml:lang="en">RHSA-2003:285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8593" xml:lang="en">8593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8600" xml:lang="en">8600</vuln:reference>
    </vuln:references>
    <vuln:summary>saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0776">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane-backend:1.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sane:sane:1.0.0</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.3</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.4</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.5</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.6</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.8</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.9</vuln:product>
      <vuln:product>cpe:/a:sane:sane-backend:1.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0776</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" xml:lang="en">CSSA-2004-005.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-379" xml:lang="en">DSA-379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" xml:lang="en">MDKSA-2003:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_046_sane.html" xml:lang="en">SuSE-SA:2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-278.html" xml:lang="en">RHSA-2003:278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-285.html" xml:lang="en">RHSA-2003:285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8593" xml:lang="en">8593</vuln:reference>
    </vuln:references>
    <vuln:summary>saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0777">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane-backend:1.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sane:sane:1.0.0</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.3</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.4</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.5</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.6</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.8</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.9</vuln:product>
      <vuln:product>cpe:/a:sane:sane-backend:1.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0777</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" xml:lang="en">CSSA-2004-005.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-379" xml:lang="en">DSA-379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" xml:lang="en">MDKSA-2003:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_046_sane.html" xml:lang="en">SuSE-SA:2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-278.html" xml:lang="en">RHSA-2003:278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-285.html" xml:lang="en">RHSA-2003:285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8593" xml:lang="en">8593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8597" xml:lang="en">8597</vuln:reference>
    </vuln:references>
    <vuln:summary>saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0778">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sane:sane-backend:1.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sane:sane:1.0.0</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.3</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.4</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.5</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.6</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.8</vuln:product>
      <vuln:product>cpe:/a:sane:sane:1.0.9</vuln:product>
      <vuln:product>cpe:/a:sane:sane-backend:1.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0778</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" xml:lang="en">CSSA-2004-005.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-379" xml:lang="en">DSA-379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" xml:lang="en">MDKSA-2003:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_046_sane.html" xml:lang="en">SuSE-SA:2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-278.html" xml:lang="en">RHSA-2003:278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-285.html" xml:lang="en">RHSA-2003:285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8593" xml:lang="en">8593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8596" xml:lang="en">8596</vuln:reference>
    </vuln:references>
    <vuln:summary>saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0779">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digium:asterisk:0.1.7</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:0.1.8</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:0.1.9</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:0.1.9.1</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:0.2</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:0.3</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0779</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a091103-1.txt" xml:lang="en">A091103-1</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0780">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.9"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.10"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.22"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.23"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.24"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.25"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.26"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.27"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.28"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.28:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.29"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.30"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.31"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.32"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.33"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.34"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.36"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.37"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.38"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.39"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.40"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.41"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.42"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.43"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.44"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.45"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.46"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.47"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.48"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.49"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.50"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.51"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.52"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.55"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.56"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.7:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.8:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.9:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.11:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:mysql:4.1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.2</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.3</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.4</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.5</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.8</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.9</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.10</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.22</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.23</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.24</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.25</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.26</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.27</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.28</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.28:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.29</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.30</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.31</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.32</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.33</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.34</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.36</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.37</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.38</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.39</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.40</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.41</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.42</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.43</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.44</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.45</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.46</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.47</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.48</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.49</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.50</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.51</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.52</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.55</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.56</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.4</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.5a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.7:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.8</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.8:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.9</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.9:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.10</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.11</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.11:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.12</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.13</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.14</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:7.0</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:conectiva:linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0780</vuln:cve-id>
    <vuln:published-datetime>2003-09-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-07T12:42:21.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" xml:lang="en">CLA-2003:743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009819.html" xml:lang="en">20030910 Buffer overflow in MySQL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106364207129993&amp;w=2" xml:lang="en">20030913 exploit for mysql -- [get_salt_from_password] problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106381424420775&amp;w=2" xml:lang="en">2003-0034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-381" xml:lang="en">DSA-381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/516492" xml:lang="en">VU#516492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:094" xml:lang="en">MDKSA-2003:094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-281.html" xml:lang="en">RHSA-2003:281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-282.html" xml:lang="en">RHSA-2003:282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/337012" xml:lang="en">20030910 Buffer overflow in MySQL</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0781">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ecartis:ecartis:1.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ecartis:ecartis:1.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0781</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:35.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-467" xml:lang="en">DSA-467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12929" xml:lang="en">ecartis-subscribe-password-disclosure(12929)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0782">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ecartis:ecartis:1.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ecartis:ecartis:1.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0782</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-467" xml:lang="en">DSA-467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12928" xml:lang="en">ecartis-multiple-bo(12928)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0783">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yongguang_zhang:hztty:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yongguang_zhang:hztty:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0783</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106424495804417&amp;w=2" xml:lang="en">20030921 Fw: 0x333hztty => hztty 2.0 local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007756" xml:lang="en">1007756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007757" xml:lang="en">1007757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-385" xml:lang="en">DSA-385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8656" xml:lang="en">8656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13243" xml:lang="en">hztty-bo(13243)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0784">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0784</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:25.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY47764&amp;apar=only" xml:lang="en">IY47764</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0785">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:brian_bassett:ipmasq:3.5.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:brian_bassett:ipmasq:3.5.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0785</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:26.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-389" xml:lang="en">DSA-389</vuln:reference>
    </vuln:references>
    <vuln:summary>ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0786">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7.1p1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.7.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.7.1p1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0786</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:26.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html" xml:lang="en">20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/602204" xml:lang="en">VU#602204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssh.com/txt/sshpam.adv" xml:lang="en">http://www.openssh.com/txt/sshpam.adv</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/338616" xml:lang="en">20030923 Portable OpenSSH 3.7.1p2 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/338617" xml:lang="en">20030923 Multiple PAM vulnerabilities in portable OpenSSH</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8677" xml:lang="en">8677</vuln:reference>
    </vuln:references>
    <vuln:summary>The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0787">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.7.1p1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.7.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.7.1p1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0787</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:26.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html" xml:lang="en">20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/209807" xml:lang="en">VU#209807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssh.com/txt/sshpam.adv" xml:lang="en">http://www.openssh.com/txt/sshpam.adv</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/338616" xml:lang="en">20030923 Portable OpenSSH 3.7.1p2 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/338617" xml:lang="en">20030923 Multiple PAM vulnerabilities in portable OpenSSH</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8677" xml:lang="en">8677</vuln:reference>
    </vuln:references>
    <vuln:summary>The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0788">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.0.4_8"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4_2"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4_3"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4_5"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:easy_software_products:cups:1.0.4</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.0.4_8</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.1</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4_2</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4_3</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4_5</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.6</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.7</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.10</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.12</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.13</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.14</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.15</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.16</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.17</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0788</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000779" xml:lang="en">CLA-2003:779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000788" xml:lang="en">CLA-2003:788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:104" xml:lang="en">MDKSA-2003:104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-275.html" xml:lang="en">RHSA-2003:275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8952" xml:lang="en">8952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-63.txt" xml:lang="en">TLSA-2003-63</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13584" xml:lang="en">cups-ipp-dos(13584)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0789">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0789</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://apache.secsup.org/dist/httpd/Announcement2.html" xml:lang="en">http://apache.secsup.org/dist/httpd/Announcement2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000775" xml:lang="en">CLA-2003:775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00045.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106761802305141&amp;w=2" xml:lang="en">20031031 GLSA:  apache (200310-04)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200310-04.xml" xml:lang="en">200310-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-015.shtml" xml:lang="en">O-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103" xml:lang="en">MDKSA-2003:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-320.html" xml:lang="en">RHSA-2003:320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6079" xml:lang="en">HPSBUX0311-301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8926" xml:lang="en">8926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13552" xml:lang="en">apache-modcgi-info-disclosure(13552)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" xml:lang="en">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0790">
    <vuln:cve-id>CVE-2003-0790</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:28.117-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: the reported issue is not a vulnerability or exposure.  Notes: This candidate was assigned to a "head-reading" bug in a component of fetchmail 6.2.4 and earlier, which was claimed to allow a denial of service.  However, the bug is in a broken component of fetchmail that is not "reachable" by any execution path, so it cannot be triggered by any sort of attack and is not exploitable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0791">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.35"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.48"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.35</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.48</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:beta</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0791</vuln:cve-id>
    <vuln:published-datetime>2003-10-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:29.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T17:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" xml:lang="en">MDKSA-2004:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6979" xml:lang="en">SCOSA-2004.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9322" xml:lang="en">9322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=221526" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=221526</vuln:reference>
    </vuln:references>
    <vuln:summary>The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0792">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:4.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:5.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fetchmail:fetchmail:6.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.6</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.7</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.5.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.6</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.7</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.6.9</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.6</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:4.7.7</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.6</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.7</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.0.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.1.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.1.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.2.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.2.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.2.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.2.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.2.7</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.2.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.3.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.3.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.3.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.3.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.4.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.4.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.4.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.4.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.5.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.5.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.5.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.5.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.5.6</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.6.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.7.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.7.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.7.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.6</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.11</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.13</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.14</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.8.17</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.4</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.5</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.8</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.10</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.11</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:5.9.13</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.0.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.1.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.1.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.2.0</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.2.1</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.2.2</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.2.3</vuln:product>
      <vuln:product>cpe:/a:fetchmail:fetchmail:6.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0792</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-004.0/CSSA-2004-004.0.txt" xml:lang="en">CSSA-2004-004.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107731542827401&amp;w=2" xml:lang="en">20040220 LNSA-#2004-0002: Fetchmail 6.2.4 and earlier remote denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-10.xml" xml:lang="en">GLSA-200403-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:101" xml:lang="en">MDKSA-2003:101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5987" xml:lang="en">IMNX-2003-7+-023-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8843" xml:lang="en">8843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-61.txt" xml:lang="en">TLSA-2003-61</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13450" xml:lang="en">fetchmail-email-dos(13450)</vuln:reference>
    </vuln:references>
    <vuln:summary>Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0793">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gdm:2.2.5.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.5</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.6</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0793</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome" xml:lang="en">http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000766" xml:lang="en">CLA-2003:766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:100" xml:lang="en">MDKSA-2003:100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8846" xml:lang="en">8846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13447" xml:lang="en">gdm-dos(13447)</vuln:reference>
    </vuln:references>
    <vuln:summary>GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0794">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdm:2.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gdm:2.2.5.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.5</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.1.6</vuln:product>
      <vuln:product>cpe:/a:gnome:gdm:2.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0794</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome" xml:lang="en">http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000766" xml:lang="en">CLA-2003:766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:100" xml:lang="en">MDKSA-2003:100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8846" xml:lang="en">8846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13448" xml:lang="en">gdm-command-dos(13448)</vuln:reference>
    </vuln:references>
    <vuln:summary>GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0795">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.91a"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.92a"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.93a"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.93b"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga:0.96"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga:0.96.1"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga:0.96.2"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga:0.96.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:zebra:0.91a</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.92a</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.93a</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.93b</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga:0.95</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga:0.96</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga:0.96.1</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga:0.96.2</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga:0.96.3</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.2.1</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0795</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:28.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106883387304266&amp;w=2" xml:lang="en">20031114 Quagga remote vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-415" xml:lang="en">DSA-415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-305.html" xml:lang="en">RHSA-2003:305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-307.html" xml:lang="en">RHSA-2003:307</vuln:reference>
    </vuln:references>
    <vuln:summary>The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0796">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0796</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031102-01-P.asc" xml:lang="en">20031102-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031102-02-P.asc" xml:lang="en">20031102-02-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9085" xml:lang="en">9085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13807" xml:lang="en">rpcmountd-mount-gain-access(13807)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0797">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0797</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:36.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031102-01-P.asc" xml:lang="en">20031102-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031102-02-P.asc" xml:lang="en">20031102-02-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9084" xml:lang="en">9084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13808" xml:lang="en">rpcmountd-dos(13808)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0798">
    <vuln:cve-id>CVE-2003-0798</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.027-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.027-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0799">
    <vuln:cve-id>CVE-2003-0799</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.040-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.040-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0800">
    <vuln:cve-id>CVE-2003-0800</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.073-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.073-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0801">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nokia:electronic_documentation:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:electronic_documentation:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0801</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:29.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a091503-1.txt" xml:lang="en">A091503-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0802">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nokia:electronic_documentation:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:electronic_documentation:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0802</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:30.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a091503-1.txt" xml:lang="en">A091503-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0803">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nokia:electronic_documentation:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:electronic_documentation:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0803</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:30.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a091503-1.txt" xml:lang="en">A091503-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0804">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0804</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:30.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:14.arp.asc" xml:lang="en">FreeBSD-SA-03:14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc" xml:lang="en">20040502-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:summary>The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0805">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd:3.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:2.0.3</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:2.0.4</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:2.3</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:2.3.1</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:3.0.0</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:3.0.1</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:3.0.2</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:3.0.3</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:3.0.4</vuln:product>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd:3.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0805</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:29.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105804485302211&amp;w=2" xml:lang="en">20030712 UMN gopherd[2.x.x/3.x.x]: ftp gateway, and GSisText() buffer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106123498310717&amp;w=2" xml:lang="en">20030818 FW: [gopher] UMN Gopher 3.0.6 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-387" xml:lang="en">DSA-387</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0806">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0806</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:06.303-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1054" name="oval:org.mitre.oval:def:1054"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A895" name="oval:org.mitre.oval:def:895"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A896" name="oval:org.mitre.oval:def:896"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/471260" xml:lang="en">VU#471260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10126" xml:lang="en">10126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15702" xml:lang="en">win-winlogon-bo(15702)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0807">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0807</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:07.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1030" name="oval:org.mitre.oval:def:1030"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A969" name="oval:org.mitre.oval:def:969"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A995" name="oval:org.mitre.oval:def:995"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2004/Apr/1009762.html" xml:lang="en">1009762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-115.shtml" xml:lang="en">O-115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/698564" xml:lang="en">VU#698564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10123" xml:lang="en">10123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012" xml:lang="en">MS04-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15709" xml:lang="en">win-cis-rpc-http-dos(15709)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0809">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0809</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:08.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A123" name="oval:org.mitre.oval:def:123"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8565" xml:lang="en">8565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-040" xml:lang="en">MS03-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13300" xml:lang="en">ie-xmlobject-code-execution(13300)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0812">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0812</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A331" name="oval:org.mitre.oval:def:331"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A575" name="oval:org.mitre.oval:def:575"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106859247713009&amp;w=2" xml:lang="en">20031111 EEYE: Windows Workstation Service Remote Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106865197102041&amp;w=2" xml:lang="en">20031112 Proof of concept for Windows Workstation Service overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-28.html" xml:lang="en">CA-2003-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20040129-ms03-049.shtml" xml:lang="en">20040129 Buffer Overrun in Microsoft Windows 2000 Workstation Service (MS03-049)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/567620" xml:lang="en">VU#567620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9011" xml:lang="en">9011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-049" xml:lang="en">MS03-049</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0813">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0813</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A893" name="oval:org.mitre.oval:def:893"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A894" name="oval:org.mitre.oval:def:894"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A900" name="oval:org.mitre.oval:def:900"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.html" xml:lang="en">20031010 Re : [VERY] BAD news on RPC DCOM Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.html" xml:lang="en">20031010 Re: Bad news on RPC DCOM vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.html" xml:lang="en">20031011 Bad news on RPC DCOM2 vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106579825211708&amp;w=2" xml:lang="en">20031010 Bad news on RPC DCOM vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106588827513795&amp;w=2" xml:lang="en">20031011 RE: Bad news on RPC DCOM vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106580303918155&amp;w=2" xml:lang="en">20031010 Bad news on RPC DCOM vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/547820" xml:lang="en">VU#547820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8811" xml:lang="en">8811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securitylab.ru/_exploits/rpc2.c.txt" xml:lang="en">http://www.securitylab.ru/_exploits/rpc2.c.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/155" xml:lang="en">20031014 Microsoft RPC Race Condition Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012" xml:lang="en">MS04-012</vuln:reference>
    </vuln:references>
    <vuln:summary>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0814">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0814</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:12.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A335" name="oval:org.mitre.oval:def:335"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A341" name="oval:org.mitre.oval:def:341"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A342" name="oval:org.mitre.oval:def:342"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A343" name="oval:org.mitre.oval:def:343"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A344" name="oval:org.mitre.oval:def:344"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A349" name="oval:org.mitre.oval:def:349"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A392" name="oval:org.mitre.oval:def:392"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007687" xml:lang="en">1007687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0177.html" xml:lang="en">20030910 MSIE->BodyRefreshLoadsJPU:refresh is a new navigation method</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/326412" xml:lang="en">VU#326412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/BodyRefreshLoadsJPU/BodyRefreshLoadsJPU-Content.htm" xml:lang="en">http://www.safecenter.net/liudieyu/BodyRefreshLoadsJPU/BodyRefreshLoadsJPU-Content.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/337086" xml:lang="en">20030911 LiuDieYu's missing files are here.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048" xml:lang="en">MS03-048</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0815">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0815</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:13.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351" name="oval:org.mitre.oval:def:351"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352" name="oval:org.mitre.oval:def:352"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353" name="oval:org.mitre.oval:def:353"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356" name="oval:org.mitre.oval:def:356"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357" name="oval:org.mitre.oval:def:357"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359" name="oval:org.mitre.oval:def:359"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472" name="oval:org.mitre.oval:def:472"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106321757619047&amp;w=2" xml:lang="en">20030910 MSIE->LinkillerJPU:another caller-based authorization(is broken).</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106322542104656&amp;w=2" xml:lang="en">20030910 MSIE->Findeath: break caller-based authorization</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007687" xml:lang="en">1007687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-021.shtml" xml:lang="en">O-021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html" xml:lang="en">20030910 MSIE->LinkillerSaveRef:another caller-based authorization</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/337086" xml:lang="en">20030911 LiuDieYu's missing files are here.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9014" xml:lang="en">9014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048" xml:lang="en">MS03-048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13676" xml:lang="en">ie-pointer-zone-bypass(13676)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0816">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0816</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:17.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361" name="oval:org.mitre.oval:def:361"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362" name="oval:org.mitre.oval:def:362"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363" name="oval:org.mitre.oval:def:363"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409" name="oval:org.mitre.oval:def:409"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416" name="oval:org.mitre.oval:def:416"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459" name="oval:org.mitre.oval:def:459"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479" name="oval:org.mitre.oval:def:479"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106321638416884&amp;w=2" xml:lang="en">20030910 MSIE->RefBack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106321693517858&amp;w=2" xml:lang="en">20030910 MSIE->NAFjpuInHistory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106321781819727&amp;w=2" xml:lang="en">20030910 MSIE->WsFakeSrc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106321882821788&amp;w=2" xml:lang="en">20030910 MSIE->WsOpenFileJPU</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106322063729496&amp;w=2" xml:lang="en">20030910 MSIE->WsBASEjpu</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106322240132721&amp;w=2" xml:lang="en">20030910 MSIE->BackMyParent2:Multi-Thread version</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007687" xml:lang="en">1007687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html" xml:lang="en">20030910 MSIE->WsOpenJpuInHistory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/652452" xml:lang="en">VU#652452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/771604" xml:lang="en">VU#771604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm" xml:lang="en">http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM" xml:lang="en">http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM" xml:lang="en">http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM" xml:lang="en">http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM" xml:lang="en">http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM" xml:lang="en">http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM" xml:lang="en">http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/336937" xml:lang="en">20030910 MSIE->NAFfileJPU</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/337086" xml:lang="en">20030911 LiuDieYu's missing files are here.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048" xml:lang="en">MS03-048</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0817">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0817</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:21.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A508" name="oval:org.mitre.oval:def:508"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A520" name="oval:org.mitre.oval:def:520"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A543" name="oval:org.mitre.oval:def:543"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A548" name="oval:org.mitre.oval:def:548"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A549" name="oval:org.mitre.oval:def:549"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A556" name="oval:org.mitre.oval:def:556"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A566" name="oval:org.mitre.oval:def:566"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9012" xml:lang="en">9012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048" xml:lang="en">MS03-048</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0818">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0818</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A653" name="oval:org.mitre.oval:def:653"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A796" name="oval:org.mitre.oval:def:796"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A797" name="oval:org.mitre.oval:def:797"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A799" name="oval:org.mitre.oval:def:799"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107643836125615&amp;w=2" xml:lang="en">20040210 EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107643892224825&amp;w=2" xml:lang="en">20040210 EEYE: Microsoft ASN.1 Library Bit String Heap Corruption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=107650972617367&amp;w=2" xml:lang="en">20040210 EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=107650972723080&amp;w=2" xml:lang="en">20040210 EEYE: Microsoft ASN.1 Library Bit String Heap Corruption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/216324" xml:lang="en">VU#216324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/583108" xml:lang="en">VU#583108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-041A.html" xml:lang="en">TA04-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-007" xml:lang="en">MS04-007</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0819">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:proxy_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:proxy_server:2.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:proxy_server:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:proxy_server:2.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0819</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:24.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A478" name="oval:org.mitre.oval:def:478"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2004-01.html" xml:lang="en">CA-2004-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/749342" xml:lang="en">VU#749342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9406" xml:lang="en">9406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9408" xml:lang="en">9408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008698" xml:lang="en">1008698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-001" xml:lang="en">MS04-001</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0820">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:::ko"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:::zh"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:sr2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::ko"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::zh"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:sr1::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:sr2::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:::ko"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:::zh"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sr1a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:97</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:::ko</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:::zh</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:sr2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::ko</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::zh</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:sr1::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:sr2::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:::ko</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:::zh</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sr1a</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2001</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0820</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:25.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A336" name="oval:org.mitre.oval:def:336"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A585" name="oval:org.mitre.oval:def:585"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A586" name="oval:org.mitre.oval:def:586"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A668" name="oval:org.mitre.oval:def:668"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0163.html" xml:lang="en">20031015 Few issues previously unpublished in English</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.security.nnov.ru/search/document.asp?docid=5243" xml:lang="en">http://www.security.nnov.ru/search/document.asp?docid=5243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8835" xml:lang="en">8835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-050" xml:lang="en">MS03-050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13682" xml:lang="en">word-macro-execute-code(13682)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0821">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:::ko"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:::zh"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97:sr2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::ko"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:::zh"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:sr1::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:98:sr2::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:::ko"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:::zh"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sr1a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:97</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:::ko</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:::zh</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97:sr2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::ko</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:::zh</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:sr1::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:98:sr2::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:::ja</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:::ko</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:::zh</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000:sr1a</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2001</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0821</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:26.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A636" name="oval:org.mitre.oval:def:636"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A675" name="oval:org.mitre.oval:def:675"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A695" name="oval:org.mitre.oval:def:695"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9010" xml:lang="en">9010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-050" xml:lang="en">MS03-050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13681" xml:lang="en">excel-macro-execute-code(13681)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0822">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage_server_extensions:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage_server_extensions:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_team_services:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:frontpage_server_extensions:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage_server_extensions:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_team_services:2002</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0822</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:12.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A364" name="oval:org.mitre.oval:def:364"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A366" name="oval:org.mitre.oval:def:366"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A367" name="oval:org.mitre.oval:def:367"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A699" name="oval:org.mitre.oval:def:699"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A743" name="oval:org.mitre.oval:def:743"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106865318904055&amp;w=2" xml:lang="en">20031112 Frontpage Extensions Remote Command Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106862654906759&amp;w=2" xml:lang="en">20031112 Frontpage Extensions Remote Command Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/279156" xml:lang="en">VU#279156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-051" xml:lang="en">MS03-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13674" xml:lang="en">fpse-debug-bo(13674)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0823">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0823</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:29.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A368" name="oval:org.mitre.oval:def:368"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A369" name="oval:org.mitre.oval:def:369"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A370" name="oval:org.mitre.oval:def:370"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A371" name="oval:org.mitre.oval:def:371"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A372" name="oval:org.mitre.oval:def:372"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A588" name="oval:org.mitre.oval:def:588"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A733" name="oval:org.mitre.oval:def:733"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106322197932006&amp;w=2" xml:lang="en">20030910 MSIE->HijackClick: 1+1=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/413886" xml:lang="en">VU#413886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/337086" xml:lang="en">20030911 LiuDieYu's missing files are here.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006036" xml:lang="en">1006036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048" xml:lang="en">MS03-048</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0824">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage_server_extensions:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage_server_extensions:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_team_services:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:frontpage_server_extensions:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage_server_extensions:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_team_services:2002</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0824</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:12.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A308" name="oval:org.mitre.oval:def:308"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A591" name="oval:org.mitre.oval:def:591"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A606" name="oval:org.mitre.oval:def:606"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A625" name="oval:org.mitre.oval:def:625"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A762" name="oval:org.mitre.oval:def:762"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/179012" xml:lang="en">VU#179012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-051" xml:lang="en">MS03-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13680" xml:lang="en">fpse-smarthtml-dos(13680)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0825">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0825</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A704" name="oval:org.mitre.oval:def:704"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A800" name="oval:org.mitre.oval:def:800"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A801" name="oval:org.mitre.oval:def:801"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A802" name="oval:org.mitre.oval:def:802"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-077.shtml" xml:lang="en">O-077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/445214" xml:lang="en">VU#445214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9624" xml:lang="en">9624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-006" xml:lang="en">MS04-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15037" xml:lang="en">win-wins-gsflag-dos(15037)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0826">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:lsh:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:lsh:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:lsh:1.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:lsh:1.4</vuln:product>
      <vuln:product>cpe:/a:gnu:lsh:1.4.1</vuln:product>
      <vuln:product>cpe:/a:gnu:lsh:1.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0826</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:41.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/211662" xml:lang="en">http://bugs.debian.org/211662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010496.html" xml:lang="en">20030919 lsh patch (was Re: [Full-Disclosure] new ssh exploit?)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html" xml:lang="en">http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106398939512178&amp;w=2" xml:lang="en">20030919 Remote root vuln in lsh 1.4.x</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106407188509874&amp;w=2" xml:lang="en">20030920 LSH: Buffer overrun and remote root compromise in lshd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-717" xml:lang="en">DSA-717</vuln:reference>
    </vuln:references>
    <vuln:summary>lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0827">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.2::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.1::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.2::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0827</vuln:cve-id>
    <vuln:published-datetime>2003-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:42.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106399616919636&amp;w=2" xml:lang="en">20030919 AppSecInc Security Alert: Denial of Service Vulnerability in DB2 Discovery Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY47686&amp;apar=only" xml:lang="en">IY47686</vuln:reference>
    </vuln:references>
    <vuln:summary>The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0828">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gus_and_psilord:freesweep:0.88"/>
        <cpe-lang:fact-ref name="cpe:/a:gus_and_psilord:freesweep:0.90"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gus_and_psilord:freesweep:0.88</vuln:product>
      <vuln:product>cpe:/a:gus_and_psilord:freesweep:0.90</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0828</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-391" xml:lang="en">DSA-391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8716" xml:lang="en">8716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13301" xml:lang="en">freesweep-bo(13301)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0830">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:marbles:marbles:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:marbles:marbles:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0830</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:35.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-390" xml:lang="en">DSA-390</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0831">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.7_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.7_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.7_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.8_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.8_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.9_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2.9_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.7</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.7_rc1</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.7_rc2</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.7_rc3</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.8</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.8_rc1</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.8_rc2</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.9_rc1</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2.9_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0831</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-04T21:29:00.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012072.html" xml:lang="en">20031014 Another ProFTPd root EXPLOIT ?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106441655617816&amp;w=2" xml:lang="en">20030924 [slackware-security]  ProFTPD Security Advisory (SSA:2003-259-02)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106606885611269&amp;w=2" xml:lang="en">20031013 Remote root exploit for proftpd \n bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/405348" xml:lang="en">VU#405348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:095" xml:lang="en">MDKSA-2003:095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/154" xml:lang="en">20030923 ProFTPD ASCII File Remote Compromise Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12200" xml:lang="en">proftpd-ascii-xfer-newline-bo(12200)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/107/" xml:lang="en">107</vuln:reference>
    </vuln:references>
    <vuln:summary>ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0832">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webfs:webfs:1.17</vuln:product>
      <vuln:product>cpe:/a:webfs:webfs:1.18</vuln:product>
      <vuln:product>cpe:/a:webfs:webfs:1.19</vuln:product>
      <vuln:product>cpe:/a:webfs:webfs:1.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0832</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:35.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-392" xml:lang="en">DSA-392</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0833">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:webfs:webfs:1.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webfs:webfs:1.17</vuln:product>
      <vuln:product>cpe:/a:webfs:webfs:1.18</vuln:product>
      <vuln:product>cpe:/a:webfs:webfs:1.19</vuln:product>
      <vuln:product>cpe:/a:webfs:webfs:1.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0833</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:35.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-392" xml:lang="en">DSA-392</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0834">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:open_unix:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:open_unix:8.0</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0834</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:22.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5141" name="oval:org.mitre.oval:def:5141"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P" xml:lang="en">20040801-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q4/0047.html" xml:lang="en">HPSBUX0311-297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57414" xml:lang="en">57414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=134&amp;type=vulnerabilities&amp;flashstatus=false" xml:lang="en">20040825 CDE libDtHelp LOGNAME Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/575804" xml:lang="en">VU#575804</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8973" xml:lang="en">8973</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0835">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:0.90_pre"/>
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:0.90_rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:0.90_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:1.0_pre1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mplayer:mplayer:0.90</vuln:product>
      <vuln:product>cpe:/a:mplayer:mplayer:0.90_pre</vuln:product>
      <vuln:product>cpe:/a:mplayer:mplayer:0.90_rc</vuln:product>
      <vuln:product>cpe:/a:mplayer:mplayer:0.90_rc4</vuln:product>
      <vuln:product>cpe:/a:mplayer:mplayer:0.91</vuln:product>
      <vuln:product>cpe:/a:mplayer:mplayer:1.0_pre1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0835</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:44.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000760" xml:lang="en">CLA-2003:760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106454257221455&amp;w=2" xml:lang="en">20030925 MPlayer Security Advisory #01: Remotely exploitable buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106460912721618&amp;w=2" xml:lang="en">20030926 Mplayer Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106485005213109&amp;w=2" xml:lang="en">20030929 GLSA:  media-video/mplayer (200309-15)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mplayerhq.hu/homepage/design6/news.html" xml:lang="en">http://www.mplayerhq.hu/homepage/design6/news.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0836">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.2::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1::aix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.2::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1::aix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0836</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:37.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0837">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.2::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.2::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0837</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106503709914622&amp;w=2" xml:lang="en">20031001 ptl-2003-02: IBM DB2 INVOKE Command Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8743" xml:lang="en">8743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13331" xml:lang="en">db2-invoke-bo(13331)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0838">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0838</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:33.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A204" name="oval:org.mitre.oval:def:204"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009639.html" xml:lang="en">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106304733121753&amp;w=2" xml:lang="en">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106304876523459&amp;w=2" xml:lang="en">20030908 Temporary Fix for IE Zero Day Malware RE: BAD NEWS: Microsoft Security Bulletin MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=ntbugtraq&amp;m=106302799428500&amp;w=2" xml:lang="en">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0310&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=2169" xml:lang="en">20031001 DNS/Hosts file issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8556" xml:lang="en">8556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-040" xml:lang="en">MS03-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13314" xml:lang="en">ie-popup-code-execution(13314)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0839">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0839</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:48.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106563075612028&amp;w=2" xml:lang="en">20031008 Microsoft Windows Server 2003 "Shell Folders" Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.geocities.co.jp/SiliconValley/1667/advisory08e.html" xml:lang="en">http://www.geocities.co.jp/SiliconValley/1667/advisory08e.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0840">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0840</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:50.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106563181313571&amp;w=2" xml:lang="en">20031008 HPUX dtprintinfo buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0841">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:peopletools:8.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:peopletools:8.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0841</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-08-19T11:38:36.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-08-15T13:42:51.200-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106554919000847&amp;w=2" xml:lang="en">20031007 PeopleSoft Grid Option Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0842">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dag_apt_repository:mod_gzip:1.3.26.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dag_apt_repository:mod_gzip:1.3.26.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0842</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:52.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105457180009860&amp;w=2" xml:lang="en">20030601 Mod_gzip Debug Mode Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0843">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dag_apt_repository:mod_gzip:1.3.26.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dag_apt_repository:mod_gzip:1.3.26.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0843</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:53.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105457180009860&amp;w=2" xml:lang="en">20030601 Mod_gzip Debug Mode Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0844">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dag_apt_repository:mod_gzip:1.3.26.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dag_apt_repository:mod_gzip:1.3.26.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0844</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:54.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105457180009860&amp;w=2" xml:lang="en">20030601 Mod_gzip Debug Mode Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0845">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss:3.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-0845</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:15.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300" name="oval:org.mitre.oval:def:11300"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106546044416498&amp;w=2" xml:lang="en">20031005 JBoss 3.2.1: Remote Command Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106547728803252&amp;w=2" xml:lang="en">20031006 Update JBoss 308 &amp; 321: Remote Command Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/docman/display_doc.php?docid=19314&amp;group_id=22866" xml:lang="en">http://sourceforge.net/docman/display_doc.php?docid=19314&amp;group_id=22866</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-1048.html" xml:lang="en">RHSA-2007:1048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8773" xml:lang="en">8773</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0846">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.3::pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:7.3::pro</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0846</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:57.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106546177518140&amp;w=2" xml:lang="en">20031006 Local root exploit in SuSE Linux 7.3Pro</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106546531922379&amp;w=2" xml:lang="en">20031006 Re: Local root exploit in SuSE Linux 8.2Pro</vuln:reference>
    </vuln:references>
    <vuln:summary>SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0847">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2::professional"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:8.2::professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0847</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:37:58.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106545972615578&amp;w=2" xml:lang="en">20031006 Local root exploit in SuSE Linux 8.2Pro</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106546531922379&amp;w=2" xml:lang="en">20031006 Re: Local root exploit in SuSE Linux 8.2Pro</vuln:reference>
    </vuln:references>
    <vuln:summary>SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0848">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:slocate:slocate:2.1</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.2</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.3</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.4</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.5</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0848</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:15.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11033" name="oval:org.mitre.oval:def:11033"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A821" name="oval:org.mitre.oval:def:821"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2004-001.0/CSSA-2004-001.0.txt" xml:lang="en">CSSA-2004-001.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106546447321274&amp;w=2" xml:lang="en">20031006 SA-20031006 slocate vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106589631819348&amp;w=2" xml:lang="en">20031011 SA-20031006 slocate buffer overflow - exploitation proof</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-040.html" xml:lang="en">RHSA-2004:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-428" xml:lang="en">DSA-428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ebitech.sk/patrik/SA/SA-20031006.txt" xml:lang="en">http://www.ebitech.sk/patrik/SA/SA-20031006.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt" xml:lang="en">http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:004" xml:lang="en">MDKSA-2004:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00009.html" xml:lang="en">FEDORA-2004-059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-041.html" xml:lang="en">RHSA-2004:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/misc/2004/TSL-2004-0005-slocate.asc.txt" xml:lang="en">2004-0005</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0849">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.5:b1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.5:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.5:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.7:p1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.7:p2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.0.7:p3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.1.0:a6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.1.0:a8"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:cfengine:2.1.0:a9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.0</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.1</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.2</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.3</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.4</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.5</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.5:b1</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.5:pre</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.5:pre2</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.6</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.7</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.7:p1</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.7:p2</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.0.7:p3</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.1.0:a6</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.1.0:a8</vuln:product>
      <vuln:product>cpe:/a:gnu:cfengine:2.1.0:a9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0849</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:00.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106451047819552&amp;w=2" xml:lang="en">20030925 Cfengine2 cfservd remote stack overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106485375218280&amp;w=2" xml:lang="en">20030928 cfengine2-2.0.3 remote exploit for redhat</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106546086216984&amp;w=2" xml:lang="en">20031005 GLSA: cfengine (200310-02)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0850">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dug_song:dsniff:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rafal_wojtczuk:libnids:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rafal_wojtczuk:libnids:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rafal_wojtczuk:libnids:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rafal_wojtczuk:libnids:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rafal_wojtczuk:libnids:1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:rafal_wojtczuk:libnids:1.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dug_song:dsniff:2.3</vuln:product>
      <vuln:product>cpe:/a:rafal_wojtczuk:libnids:1.11</vuln:product>
      <vuln:product>cpe:/a:rafal_wojtczuk:libnids:1.12</vuln:product>
      <vuln:product>cpe:/a:rafal_wojtczuk:libnids:1.13</vuln:product>
      <vuln:product>cpe:/a:rafal_wojtczuk:libnids:1.14</vuln:product>
      <vuln:product>cpe:/a:rafal_wojtczuk:libnids:1.16</vuln:product>
      <vuln:product>cpe:/a:rafal_wojtczuk:libnids:1.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0850</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:02.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000773" xml:lang="en">CLA-2003:773</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106728224210446&amp;w=2" xml:lang="en">20031027 Libnids &lt;= 1.17 buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=191323" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=191323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-410" xml:lang="en">DSA-410</vuln:reference>
    </vuln:references>
    <vuln:summary>The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0851">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sx"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:cisco:css11000_content_services_switch"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:pix_firewall:6.2.2_.111"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%284.101%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%285%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.3%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.3%283.102%29"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:css11000_content_services_switch</vuln:product>
      <vuln:product>cpe:/a:cisco:pix_firewall:6.2.2_.111</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811%29e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%284.101%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%285%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.3%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.3%283.102%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0851</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:18.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5528" name="oval:org.mitre.oval:def:5528"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.asc" xml:lang="en">NetBSD-SA2004-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc" xml:lang="en">20040304-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106796246511667&amp;w=2" xml:lang="en">20031104 [OpenSSL Advisory] Denial of Service in ASN.1 parsing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108403850228012&amp;w=2" xml:lang="en">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-119.html" xml:lang="en">RHSA-2004:119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030930-ssl.shtml" xml:lang="en">20030930 SSL Implementation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/412478" xml:lang="en">VU#412478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20031104.txt" xml:lang="en">http://www.openssl.org/news/secadv_20031104.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html" xml:lang="en">FEDORA-2005-1042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8970" xml:lang="en">8970</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0852">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sylpheed:sylpheed:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sylpheed:sylpheed:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sylpheed:sylpheed:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sylpheed-claws:sylpheed-claws:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sylpheed-claws:sylpheed-claws:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sylpheed-claws:sylpheed-claws:0.9.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sylpheed:sylpheed:0.9.4</vuln:product>
      <vuln:product>cpe:/a:sylpheed:sylpheed:0.9.5</vuln:product>
      <vuln:product>cpe:/a:sylpheed:sylpheed:0.9.6</vuln:product>
      <vuln:product>cpe:/a:sylpheed-claws:sylpheed-claws:0.9.4</vuln:product>
      <vuln:product>cpe:/a:sylpheed-claws:sylpheed-claws:0.9.5</vuln:product>
      <vuln:product>cpe:/a:sylpheed-claws:sylpheed-claws:0.9.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0852</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012542.html" xml:lang="en">20031022 Sylpheed-claws format string bug, yet still sylpheed much better than windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sylpheed.good-day.net/#changes" xml:lang="en">http://sylpheed.good-day.net/#changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.guninski.com/sylph.html" xml:lang="en">http://www.guninski.com/sylph.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8877" xml:lang="en">8877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13508" xml:lang="en">sylpheed-smtp-format-string(13508)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0853">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta2::academ"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_vr16"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_vr17"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:fileutils:4.0</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.0.36</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.1</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.1.6</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.1.7</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta2::academ</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_vr16</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_vr17</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.5.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0853</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:44.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000768" xml:lang="en">CLA-2003:768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000771" xml:lang="en">CLA-2003:771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012548.html" xml:lang="en">20031022 Fun with /bin/ls, yet still ls better than windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.guninski.com/binls.html" xml:lang="en">http://www.guninski.com/binls.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:106" xml:lang="en">MDKSA-2003:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-309.html" xml:lang="en">RHSA-2003:309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-310.html" xml:lang="en">RHSA-2003:310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6014" xml:lang="en">IMNX-2003-7+-026-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8875" xml:lang="en">8875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-60.txt" xml:lang="en">TLSA-2003-60</vuln:reference>
    </vuln:references>
    <vuln:summary>An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0854">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:fileutils:4.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta2::academ"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_vr16"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_vr17"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:fileutils:4.0</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.0.36</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.1</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.1.6</vuln:product>
      <vuln:product>cpe:/a:gnu:fileutils:4.1.7</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta2::academ</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_vr16</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_vr17</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.5.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0854</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:15.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000768" xml:lang="en">CLA-2003:768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000771" xml:lang="en">CLA-2003:771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012548.html" xml:lang="en">20031022 Fun with /bin/ls, yet still ls better than windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-705" xml:lang="en">DSA-705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.guninski.com/binls.html" xml:lang="en">http://www.guninski.com/binls.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:106" xml:lang="en">MDKSA-2003:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-309.html" xml:lang="en">RHSA-2003:309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-310.html" xml:lang="en">RHSA-2003:310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6014" xml:lang="en">IMNX-2003-7+-026-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-60.txt" xml:lang="en">TLSA-2003-60</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/115" xml:lang="en">115</vuln:reference>
    </vuln:references>
    <vuln:summary>ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0855">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:charles_kerr:pan:0.13.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:charles_kerr:pan:0.13.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0855</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:26.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.gnome.org/show_bug.cgi?id=107025" xml:lang="en">http://bugzilla.gnome.org/show_bug.cgi?id=107025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=107519" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=107519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-311.html" xml:lang="en">RHSA-2003:311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-312.html" xml:lang="en">RHSA-2003:312</vuln:reference>
    </vuln:references>
    <vuln:summary>Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0856">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stephen_hemminger:iproute:2.4.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stephen_hemminger:iproute:2.4.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0856</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:15.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10912" name="oval:org.mitre.oval:def:10912"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-492" xml:lang="en">DSA-492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_01_sr.html" xml:lang="en">SUSE-SR:2005:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00004.html" xml:lang="en">FEDORA-2004-115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-316.html" xml:lang="en">RHSA-2003:316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-317.html" xml:lang="en">RHSA-2003:317</vuln:reference>
    </vuln:references>
    <vuln:summary>iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0857">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0857</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:26.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-11-29T11:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=108574" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=108574</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0858">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga_routing_software_suite:0.95"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:zebra:0.91</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga_routing_software_suite:0.95</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0858</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:15.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10169" name="oval:org.mitre.oval:def:10169"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-415" xml:lang="en">DSA-415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-305.html" xml:lang="en">RHSA-2003:305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-307.html" xml:lang="en">RHSA-2003:307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-315.html" xml:lang="en">RHSA-2003:315</vuln:reference>
    </vuln:references>
    <vuln:summary>Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0859">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.91a"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.92a"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.93a"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:zebra:0.93b"/>
        <cpe-lang:fact-ref name="cpe:/a:quagga:quagga_routing_software_suite:0.96.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:intel:ia64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:glibc:2.3.2</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.91a</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.92a</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.93a</vuln:product>
      <vuln:product>cpe:/a:gnu:zebra:0.93b</vuln:product>
      <vuln:product>cpe:/a:quagga:quagga_routing_software_suite:0.96.2</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.2.1</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/h:intel:ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0859</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:15.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11337" name="oval:org.mitre.oval:def:11337"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-325.html" xml:lang="en">RHSA-2003:325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-334.html" xml:lang="en">RHSA-2003:334</vuln:reference>
    </vuln:references>
    <vuln:summary>The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0860">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0860</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php#4.3.3" xml:lang="en">http://www.php.net/ChangeLog-4.php#4.3.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/release_4_3_3.php" xml:lang="en">http://www.php.net/release_4_3_3.php</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0861">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0861</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php#4.3.3" xml:lang="en">http://www.php.net/ChangeLog-4.php#4.3.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/release_4_3_3.php" xml:lang="en">http://www.php.net/release_4_3_3.php</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0862">
    <vuln:cve-id>CVE-2003-0862</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:46.647-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0813.  Reason: This candidate is a duplicate of CVE-2003-0813.  Notes: All CVE users should reference CVE-2003-0813 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0863">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0863</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105839111204227" xml:lang="en">20030716 PHP safe mode broken?</vuln:reference>
    </vuln:references>
    <vuln:summary>The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0864">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ircnet:ircnet_ircd:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ircnet:ircnet_ircd:2.10.3_p3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ircnet:ircnet_ircd:2.10</vuln:product>
      <vuln:product>cpe:/a:ircnet:ircnet_ircd:2.10.3_p3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0864</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.irc.org/irc/server/ChangeLog" xml:lang="en">ftp://ftp.irc.org/irc/server/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000765" xml:lang="en">CLA-2003:765</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106606129601446&amp;w=2" xml:lang="en">20031012 buffer overflow in IRCD software</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106667431021928&amp;w=2" xml:lang="en">20031019 [OpenPKG-SA-2003.045] OpenPKG Security Advisory (ircd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8817" xml:lang="en">8817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13408" xml:lang="en">ircd-mjoin-bo(13408)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0865">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59r"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59s"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59r</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59s</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0865</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:07.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt" xml:lang="en">CSSA-2004-002.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000781" xml:lang="en">CLA-2003:781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106493686331198&amp;w=2" xml:lang="en">20030930 GLSA:  mpg123 (200309-17)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-435" xml:lang="en">DSA-435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/338641" xml:lang="en">20030923 mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8680" xml:lang="en">8680</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0866">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0866</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-03-25T07:29:02.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=215506" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=215506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" xml:lang="en">239312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-4.html" xml:lang="en">http://tomcat.apache.org/security-4.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-395" xml:lang="en">DSA-395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8824" xml:lang="en">8824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1979/references" xml:lang="en">ADV-2008-1979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13429" xml:lang="en">tomcat-non-http-dos(13429)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/</vuln:reference>
    </vuln:references>
    <vuln:summary>The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0867">
    <vuln:cve-id>CVE-2003-0867</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:48.243-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0662.  Reason: This candidate is a duplicate of CVE-2003-0662.  Notes: All CVE users should reference CVE-2003-0662 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0868">
    <vuln:cve-id>CVE-2003-0868</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.087-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.087-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0869">
    <vuln:cve-id>CVE-2003-0869</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.103-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.120-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0870">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0870</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0016.html" xml:lang="en">20031020 Opera HREF escaped server name overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a102003-1.txt" xml:lang="en">A102003-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8853" xml:lang="en">8853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13458" xml:lang="en">opera-escape-heap-overflow(13458)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0871">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0871</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:48.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00039.html" xml:lang="en">APPLE-SA-2003-10-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8922" xml:lang="en">8922</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0872">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0872</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:29.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.27/CSSA-2003-SCO.27.txt" xml:lang="en">CSSA-2003-SCO.27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8864" xml:lang="en">8864</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0873">
    <vuln:cve-id>CVE-2003-0873</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.137-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.137-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0874">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:deskpro:deskpro:1.1_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:deskpro:deskpro:1.1_.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0874</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html" xml:lang="en">20031020 Multiple SQL Injection Vulnerabilities in DeskPRO</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106667525623311&amp;w=2" xml:lang="en">20031020 Multiple SQL Injection Vulnerabilities in DeskPRO</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/6R0052K8KM.html" xml:lang="en">http://www.securiteam.com/unixfocus/6R0052K8KM.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8856" xml:lang="en">8856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13391" xml:lang="en">deskpro-multiple-sql-injection(13391)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0875">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openslp:openslp:1.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openslp:openslp:1.0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0875</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:09.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000723" xml:lang="en">CLA-2003:723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106123103606336&amp;w=2" xml:lang="en">20030818 OpenSLP initscript symlink vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0876">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0876</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a102803-1.txt" xml:lang="en">A102803-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8916" xml:lang="en">8916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8917" xml:lang="en">8917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13537" xml:lang="en">macos-insecure-file-permissions(13537)</vuln:reference>
    </vuln:references>
    <vuln:summary>Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0877">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0877</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a102803-1.txt" xml:lang="en">A102803-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8914" xml:lang="en">8914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8917" xml:lang="en">8917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13542" xml:lang="en">macos-core-files-symlink(13542)</vuln:reference>
    </vuln:references>
    <vuln:summary>Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0878">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0878</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:29.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:summary>slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0879">
    <vuln:cve-id>CVE-2003-0879</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:51.477-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0518.  Reason: This candidate is a reservation duplicate of CVE-2003-0518.  Notes: All CVE users should reference CVE-2003-0518 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0880">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0880</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:30.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0881">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0881</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:30.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0882">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0882</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:30.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0883">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0883</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:30.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0885">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0885</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:30.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-01T09:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=41253" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=41253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286</vuln:reference>
    </vuln:references>
    <vuln:summary>Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0886">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:hylafax:hylafax:4.1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1</vuln:product>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1.1</vuln:product>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1.2</vuln:product>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1.3</vuln:product>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1.5</vuln:product>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1.6</vuln:product>
      <vuln:product>cpe:/a:hylafax:hylafax:4.1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0886</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:11.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000783" xml:lang="en">CLA-2003:783</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106858898708752&amp;w=2" xml:lang="en">20031111 HylaFAX - Format String Vulnerability Fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-401" xml:lang="en">DSA-401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:105" xml:lang="en">MDKSA-2003:105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_045_hylafax.html" xml:lang="en">SuSE-SA:2003:045</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0887">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:angus_mackay:ez-ipupdate:3.0.11b5"/>
        <cpe-lang:fact-ref name="cpe:/a:angus_mackay:ez-ipupdate:3.0.11b7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:angus_mackay:ez-ipupdate:3.0.11b5</vuln:product>
      <vuln:product>cpe:/a:angus_mackay:ez-ipupdate:3.0.11b7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0887</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:31.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?r1=1.4&amp;r2=1.5" xml:lang="en">http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?r1=1.4&amp;r2=1.5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?rev=1.6" xml:lang="en">http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?rev=1.6</vuln:reference>
    </vuln:references>
    <vuln:summary>ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0894">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.2.0.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.2.0.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0894</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007956" xml:lang="en">1007956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/496340" xml:lang="en">VU#496340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8844" xml:lang="en">8844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8845" xml:lang="en">8845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13451" xml:lang="en">oracle-oracleo-binaries-bo(13451)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0895">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0895</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a102803-3.txt" xml:lang="en">A102803-3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8913" xml:lang="en">8913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13541" xml:lang="en">macos-long-command-bo(13541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0896">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.1:update3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.4.1:update3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0896</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:12.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lsd-pl.net/code/JVM/jre.tar.gz" xml:lang="en">http://lsd-pl.net/code/JVM/jre.tar.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106692334503819&amp;w=2" xml:lang="en">20021023 [LSD] Security vulnerability in SUN's Java Virtual Machine implementation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57221" xml:lang="en">57221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200356-1" xml:lang="en">200356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6028" xml:lang="en">HPSBUX0311-295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342580" xml:lang="en">20031027 Re: [LSD] Security vulnerability in SUN's Java Virtual Machine implementation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342583" xml:lang="en">20031027 Re: [LSD] Security vulnerability in SUN's Java Virtual Machineimplementation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8879" xml:lang="en">8879</vuln:reference>
    </vuln:references>
    <vuln:summary>The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0897">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0897</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:37.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106692772510010&amp;w=2" xml:lang="en">20031023 Shatter XP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13558" xml:lang="en">winxp-commctl32-code-execution(13558)</vuln:reference>
    </vuln:references>
    <vuln:summary>"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0898">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.0::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.1::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.0::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0898</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:14.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt" xml:lang="en">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106010332721672&amp;w=2" xml:lang="en">20030805 Local Vulnerability in IBM DB2 7.1 db2job binary</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0899">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:acme_labs:thttpd:2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:acme_labs:thttpd:2.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:acme_labs:thttpd:2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:acme_labs:thttpd:2.23b1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acme_labs:thttpd:2.21</vuln:product>
      <vuln:product>cpe:/a:acme_labs:thttpd:2.21b</vuln:product>
      <vuln:product>cpe:/a:acme_labs:thttpd:2.22</vuln:product>
      <vuln:product>cpe:/a:acme_labs:thttpd:2.23b1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0899</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106729188224252&amp;w=2" xml:lang="en">20031027 Remote overflow in thttpd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8906" xml:lang="en">8906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13530" xml:lang="en">thttpd-defang-bo(13530)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="https://www.debian.org/security/2003/dsa-396" xml:lang="en">DSA-396</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '&lt;' or '>' characters, which trigger the overflow when the characters are expanded to "&amp;lt;" and "&amp;gt;" sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0900">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0900</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:32.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T14:49:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=108711" xml:lang="en">https://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=108711</vuln:reference>
    </vuln:references>
    <vuln:summary>Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0901">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0901</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:32.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c" xml:lang="en">http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000784" xml:lang="en">CLA-2003:784</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000772" xml:lang="en">CLSA-2003:772</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-397" xml:lang="en">DSA-397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-313.html" xml:lang="en">RHSA-2003:313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-314.html" xml:lang="en">RHSA-2003:314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8741" xml:lang="en">8741</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0902">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:minimalist:minimalist:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:minimalist:minimalist:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:minimalist:minimalist:2.2</vuln:product>
      <vuln:product>cpe:/a:minimalist:minimalist:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0902</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:54.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-402" xml:lang="en">DSA-402</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0903">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.6</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.7</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0903</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:34.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A525" name="oval:org.mitre.oval:def:525"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A553" name="oval:org.mitre.oval:def:553"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A751" name="oval:org.mitre.oval:def:751"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A775" name="oval:org.mitre.oval:def:775"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/139150" xml:lang="en">VU#139150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9407" xml:lang="en">9407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-003" xml:lang="en">MS04-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14187" xml:lang="en">mdac-broadcastrequest-bo(14187)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0904">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_services:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_services:2.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0904</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:35.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A477" name="oval:org.mitre.oval:def:477"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/530660" xml:lang="en">VU#530660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/exchange/support/e2k3owa.asp" xml:lang="en">http://www.microsoft.com/exchange/support/e2k3owa.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0311&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=9281" xml:lang="en">20031114 Exchange 2003 OWA major security flaw</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9118" xml:lang="en">9118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9409" xml:lang="en">9409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-002" xml:lang="en">MS04-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13869" xml:lang="en">exchange-owa-account-access(13869)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0905">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_services:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_services:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0905</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:36.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A842" name="oval:org.mitre.oval:def:842"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/982630" xml:lang="en">VU#982630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9825" xml:lang="en">9825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-008" xml:lang="en">MS04-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15038" xml:lang="en">win-media-services-dos(15038)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0906">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0906</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:37.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1064" name="oval:org.mitre.oval:def:1064"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A897" name="oval:org.mitre.oval:def:897"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A959" name="oval:org.mitre.oval:def:959"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/547028" xml:lang="en">VU#547028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10120" xml:lang="en">10120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0907">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0907</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:38.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000" name="oval:org.mitre.oval:def:1000"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904" name="oval:org.mitre.oval:def:904"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020065.html" xml:lang="en">20040413 Microsoft Help and Support Center argument injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108196864221676&amp;w=2" xml:lang="en">20040413 [Full-Disclosure] iDEFENSE Security Advisory 04.13.04 - Microsoft Help and Support</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=100&amp;type=vulnerabilities" xml:lang="en">http://www.idefense.com/application/poi/display?id=100&amp;type=vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/260588" xml:lang="en">VU#260588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10119" xml:lang="en">10119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15704" xml:lang="en">win-hcpurl-code-execution(15704)</vuln:reference>
    </vuln:references>
    <vuln:summary>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0908">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0908</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:39.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1046" name="oval:org.mitre.oval:def:1046"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0082.html" xml:lang="en">20040414 [SHATTER Team Security Alert] Microsoft Windows Utility Manager Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.appsecinc.com/resources/alerts/general/04-0001.html" xml:lang="en">http://www.appsecinc.com/resources/alerts/general/04-0001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/526084" xml:lang="en">VU#526084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10124" xml:lang="en">10124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15632" xml:lang="en">win2k-utilitymgr-gain-privileges(15632)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0909">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0909</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:40.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1004" name="oval:org.mitre.oval:def:1004"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/206468" xml:lang="en">VU#206468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10125" xml:lang="en">10125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15678" xml:lang="en">winxp-task-gain-privileges(15678)</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0910">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0910</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:40.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890" name="oval:org.mitre.oval:def:890"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911" name="oval:org.mitre.oval:def:911"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html" xml:lang="en">20040413 EEYE: Windows Expand-Down Data Segment Local Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20040413D.html" xml:lang="en">AD20040413D</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/122076" xml:lang="en">VU#122076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10122" xml:lang="en">10122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15707" xml:lang="en">win-ldt-gain-privileges(15707)</vuln:reference>
    </vuln:references>
    <vuln:summary>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0913">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0913</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=120269" xml:lang="en">http://docs.info.apple.com/article.html?artnum=120269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00040.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00040.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8979" xml:lang="en">8979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13620" xml:lang="en">macos-terminal-gain-access(13620)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0914">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nixu:namesurfer:standard_3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nixu:namesurfer:suite_3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk8_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk4_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk4_bl21"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk5_bl23"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk2_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1l"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:current"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:8.2.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4.1</vuln:product>
      <vuln:product>cpe:/a:nixu:namesurfer:standard_3.0.1</vuln:product>
      <vuln:product>cpe:/a:nixu:namesurfer:suite_3.0.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk8_bl22</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk4_bl22</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk4_bl21</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk5_bl23</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk2_bl22</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1l</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:current</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0914</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2011" name="oval:org.mitre.oval:def:2011"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-003.0/CSSA-2004-003.0.txt" xml:lang="en">CSSA-2004-003.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.33/CSSA-2003-SCO.33.txt" xml:lang="en">CSSA-2003-SCO.33</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57434" xml:lang="en">57434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-409" xml:lang="en">DSA-409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/734644" xml:lang="en">VU#734644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/misc/2003/TSL-2003-0044-bind.asc.txt" xml:lang="en">2003-0044</vuln:reference>
    </vuln:references>
    <vuln:summary>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0917">
    <vuln:cve-id>CVE-2003-0917</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.150-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.150-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0918">
    <vuln:cve-id>CVE-2003-0918</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.183-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.183-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0919">
    <vuln:cve-id>CVE-2003-0919</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.197-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.197-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0920">
    <vuln:cve-id>CVE-2003-0920</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.213-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.213-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0921">
    <vuln:cve-id>CVE-2003-0921</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.243-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.243-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0922">
    <vuln:cve-id>CVE-2003-0922</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.290-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.290-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0923">
    <vuln:cve-id>CVE-2003-0923</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.323-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.323-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0924">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netpbm:netpbm:9.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netpbm:netpbm:9.25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0924</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:14.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A804" name="oval:org.mitre.oval:def:804"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A810" name="oval:org.mitre.oval:def:810"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-426" xml:lang="en">DSA-426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200410-02.xml" xml:lang="en">GLSA-200410-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/487102" xml:lang="en">VU#487102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:011" xml:lang="en">MDKSA-2004:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-030.html" xml:lang="en">RHSA-2004:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-031.html" xml:lang="en">RHSA-2004:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9442" xml:lang="en">9442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14874" xml:lang="en">netpbm-temp-insecure-file(14874)</vuln:reference>
    </vuln:references>
    <vuln:summary>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0925">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0925</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9692" name="oval:org.mitre.oval:def:9692"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780" xml:lang="en">CLA-2003:780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-407" xml:lang="en">DSA-407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00011.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00011.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114" xml:lang="en">MDKSA-2003:114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-323.html" xml:lang="en">RHSA-2003:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-324.html" xml:lang="en">RHSA-2003:324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8951" xml:lang="en">8951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-64.txt" xml:lang="en">TLSA-2003-64</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0926">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0926</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11648" name="oval:org.mitre.oval:def:11648"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780" xml:lang="en">CLA-2003:780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-407" xml:lang="en">DSA-407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00011.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00011.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114" xml:lang="en">MDKSA-2003:114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-323.html" xml:lang="en">RHSA-2003:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-324.html" xml:lang="en">RHSA-2003:324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8951" xml:lang="en">8951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-64.txt" xml:lang="en">TLSA-2003-64</vuln:reference>
    </vuln:references>
    <vuln:summary>Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0927">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0927</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9691" name="oval:org.mitre.oval:def:9691"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780" xml:lang="en">CLA-2003:780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-407" xml:lang="en">DSA-407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00011.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00011.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114" xml:lang="en">MDKSA-2003:114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-323.html" xml:lang="en">RHSA-2003:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-324.html" xml:lang="en">RHSA-2003:324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8951" xml:lang="en">8951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-64.txt" xml:lang="en">TLSA-2003-64</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13578" xml:lang="en">ethereal-socks-heap-overflow(13578)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0928">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0928</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:18.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109241692108678&amp;w=2" xml:lang="en">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c030807-001.txt" xml:lang="en">http://www.corsaire.com/advisories/c030807-001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0929">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0929</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:19.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109241692108678&amp;w=2" xml:lang="en">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c030807-001.txt" xml:lang="en">http://www.corsaire.com/advisories/c030807-001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0930">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0930</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:20.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109241692108678&amp;w=2" xml:lang="en">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c030807-001.txt" xml:lang="en">http://www.corsaire.com/advisories/c030807-001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0931">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sygate_technologies:enforcer:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sygate_technologies:enforcer:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0931</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109215951022437&amp;w=2" xml:lang="en">20040810 Corsaire Security Advisory - Sygate Enforcer discovery packet DoS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c031120-001.txt" xml:lang="en">http://www.corsaire.com/advisories/c031120-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16949" xml:lang="en">sygate-enforcer-payload-dos(16949)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0932">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:omega-rpg:omega-rpg:0.9.0_pa9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omega-rpg:omega-rpg:0.9.0_pa9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0932</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:56.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-400" xml:lang="en">DSA-400</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0933">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:conquest:conquest:7.1.1_-6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:conquest:conquest:7.1.1_-6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0933</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:20:57.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-398" xml:lang="en">DSA-398</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0934">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:symbol_technologies:pdt:8100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:symbol_technologies:pdt:8100</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0934</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:22.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106850011513880&amp;w=2" xml:lang="en">20031110 Symbol Technologies Default WEP KEYS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnap.net/security/031106.html" xml:lang="en">http://www.secnap.net/security/031106.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0935">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.4_pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:net-snmp:net-snmp:5.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.1</vuln:product>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.3</vuln:product>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.4_pre2</vuln:product>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.5</vuln:product>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.6</vuln:product>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.7</vuln:product>
      <vuln:product>cpe:/a:net-snmp:net-snmp:5.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0935</vuln:cve-id>
    <vuln:published-datetime>2003-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A869" name="oval:org.mitre.oval:def:869"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9802" name="oval:org.mitre.oval:def:9802"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000778" xml:lang="en">CLA-2003:778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=308015" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=308015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-335.html" xml:lang="en">RHSA-2003:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-023.html" xml:lang="en">RHSA-2004:023</vuln:reference>
    </vuln:references>
    <vuln:summary>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0936">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:pcanywhere:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:pcanywhere:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:pcanywhere:11.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:pcanywhere:10.0</vuln:product>
      <vuln:product>cpe:/a:symantec:pcanywhere:10.5</vuln:product>
      <vuln:product>cpe:/a:symantec:pcanywhere:11.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0936</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:24.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106875764826251&amp;w=2" xml:lang="en">20031113 SRT2003-11-13-0218 - PCAnywhere local SYSTEM exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106876107330752&amp;w=2" xml:lang="en">20031113 RE: Secure Network Operations SRT2003-11-13-0218, PCAnywhere allows local users to become SYSTEM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2003.11.13.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2003.11.13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0937">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:open_unix:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:open_unix:8.0</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0937</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:25.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.32/CSSA-2003-SCO.32.txt" xml:lang="en">CSSA-2003-SCO.32</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106865297403687&amp;w=2" xml:lang="en">20031112 Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.texonet.com/advisories/TEXONET-20031024.txt" xml:lang="en">http://www.texonet.com/advisories/TEXONET-20031024.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0938">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0938</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-1.txt" xml:lang="en">A111703-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13765" xml:lang="en">sapdb-NETAPI32-gain-privileges(13765)</vuln:reference>
    </vuln:references>
    <vuln:summary>vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0939">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0939</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:36.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-1.txt" xml:lang="en">A111703-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sapdb.org/7.4/new_relinfo.txt" xml:lang="en">http://www.sapdb.org/7.4/new_relinfo.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256 byte segment to the niserver (aka serv.exe) process on TCP port 7269, which prevents the server from NULL terminating the string and leads to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0940">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0940</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:36.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-2.txt" xml:lang="en">A111703-2</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0941">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0941</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:37.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-2.txt" xml:lang="en">A111703-2</vuln:reference>
    </vuln:references>
    <vuln:summary>web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0942">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0942</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:37.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-2.txt" xml:lang="en">A111703-2</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin.wa.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0943">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0943</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:37.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-2.txt" xml:lang="en">A111703-2</vuln:reference>
    </vuln:references>
    <vuln:summary>web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redirect attacks against internal databases via (1) waecho, (2) Web SQL Interface (websql), or (3) Web Database Manager (webdbm).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0944">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0944</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:37.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-2.txt" xml:lang="en">A111703-2</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL with a long requestURI.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0945">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4.03.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.4.03.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0945</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a111703-2.txt" xml:lang="en">A111703-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13774" xml:lang="en">sapdb-manager-sessionid-predictable(13774)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0946">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60p"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60p</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0946</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:26.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106867135830683&amp;w=2" xml:lang="en">20031112 SRT2003-11-11-1151 - clamav-milter remote exploit / DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=197038" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=197038</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0947">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:19"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:20"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:21"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:22"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:23"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:24"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:25"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:26"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-0947</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:27.563-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106867458902521&amp;w=2" xml:lang="en">20031112 iwconfig vulnerability - the last code was demaged sending by email</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0948">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:19"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:20"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:21"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:22"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:23"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:24"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:25"/>
        <cpe-lang:fact-ref name="cpe:/a:wireless_tools:wireless_tools:26"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:19</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:20</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:21</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:22</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:23</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:24</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:25</vuln:product>
      <vuln:product>cpe:/a:wireless_tools:wireless_tools:26</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0948</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:38.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/6Y00R1P8KY.html" xml:lang="en">http://www.securiteam.com/exploits/6Y00R1P8KY.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8901" xml:lang="en">8901</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0949">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_bischoff:xsok:1.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_bischoff:xsok:1.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0949</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-405" xml:lang="en">DSA-405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9321" xml:lang="en">9321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14098" xml:lang="en">xsok-command-execution(14098)</vuln:reference>
    </vuln:references>
    <vuln:summary>xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0950">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.19"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.20"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.42"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.4</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.19</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.20</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.42</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0950</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9041" xml:lang="en">9041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/157" xml:lang="en">20031112 IClient Servlet Remote Command Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12805" xml:lang="en">peoplesoft-iclientservlet-file-upload(12805)</vuln:reference>
    </vuln:references>
    <vuln:summary>PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0951">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0951</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5146" name="oval:org.mitre.oval:def:5146"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q4/0041.html" xml:lang="en">HPSBUX0311-296</vuln:reference>
    </vuln:references>
    <vuln:summary>Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0952">
    <vuln:cve-id>CVE-2003-0952</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.337-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.337-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0953">
    <vuln:cve-id>CVE-2003-0953</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.353-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.370-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0954">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0954</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:38.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T14:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008258" xml:lang="en">1008258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9078" xml:lang="en">9078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY48272&amp;apar=only" xml:lang="en">IY48272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY48747&amp;apar=only" xml:lang="en">IY48747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY49238&amp;apar=only" xml:lang="en">IY49238</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0955">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0955</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:28.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch" xml:lang="en">20031105 005: RELIABILITY FIX: November 4, 2003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013315.html" xml:lang="en">20031104 OpenBSD kernel overflow, yet still *BSD much better than windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=openbsd-security-announce&amp;m=106808820119679&amp;w=2" xml:lang="en">http://marc.info/?l=openbsd-security-announce&amp;m=106808820119679&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=openbsd-security-announce&amp;m=106917441524978&amp;w=2" xml:lang="en">http://marc.info/?l=openbsd-security-announce&amp;m=106917441524978&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.guninski.com/msuxobsd2.html" xml:lang="en">http://www.guninski.com/msuxobsd2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata33.html" xml:lang="en">20031104 010: RELIABILITY FIX: November 4, 2003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8978" xml:lang="en">8978</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0956">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0956</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/42942" xml:lang="en">linux-kernel-odirect-information-disclosure(42942)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cause incorrect data to be returned when a file is truncated as it is being read, which might allow local users to obtain sensitive data that was originally owned by other users, a different vulnerability than CVE-2003-0018.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0959">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-0959</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:38.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@3ed382f7UfJ9Q2LKCJq1Tc5B7-EC5A" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@3ed382f7UfJ9Q2LKCJq1Tc5B7-EC5A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/43072" xml:lang="en">linux-kernel-unspecified-priv-escalation(43072)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows attackers to cause a denial of service or gain root privileges via unspecified vectors that trigger copy_from_user function calls with improper length arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0960">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openca:openca:0.8.0</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.8.1</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.8.6</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.9.0</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.9.0.1</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.9.0.2</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.9.1</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.9.1.2</vuln:product>
      <vuln:product>cpe:/a:openca:openca:0.9.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0960</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:29.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107003609308765&amp;w=2" xml:lang="en">20031128 [OpenCA Advisory] Vulnerabilities in signature verification</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0961">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0961</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:31.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000796" xml:lang="en">CLA-2003:796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/papers/linux_kernel_do_brk.pdf" xml:lang="en">http://isec.pl/papers/linux_kernel_do_brk.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107064798706473&amp;w=2" xml:lang="en">20031204 [iSEC] Linux kernel do_brk() vulnerability details</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107064830206816&amp;w=2" xml:lang="en">20031204 Hot fix for do_brk bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107394143105081&amp;w=2" xml:lang="en">20040112 SmoothWall Project Security Advisory SWP-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-403" xml:lang="en">DSA-403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-417" xml:lang="en">DSA-417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-433" xml:lang="en">DSA-433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-439" xml:lang="en">DSA-439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-440" xml:lang="en">DSA-440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-450" xml:lang="en">DSA-450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-470" xml:lang="en">DSA-470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-475" xml:lang="en">DSA-475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/301156" xml:lang="en">VU#301156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:110" xml:lang="en">MDKSA-2003:110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_049_kernel.html" xml:lang="en">SuSE-SA:2003:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-368.html" xml:lang="en">RHSA-2003:368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-389.html" xml:lang="en">RHSA-2003:389</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0962">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:rsync:2.4.6-2::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:rsync:2.4.6-5::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:rsync:2.4.6-5::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:rsync:2.5.4-2::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:rsync:2.5.5-1::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:rsync:2.5.5-4::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:engardelinux:secure_community:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:engardelinux:secure_community:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:engardelinux:secure_linux:1.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:engardelinux:secure_linux:1.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:engardelinux:secure_linux:1.5::professional"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:current"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.3.1</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.3.2</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.0</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.1</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.3</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.4</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.5</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.6</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.4.8</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.0</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.1</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.2</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.3</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.4</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.5</vuln:product>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.5.6</vuln:product>
      <vuln:product>cpe:/a:redhat:rsync:2.4.6-2::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:rsync:2.4.6-5::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:rsync:2.4.6-5::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:rsync:2.5.4-2::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:rsync:2.5.5-1::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:rsync:2.5.5-4::i386</vuln:product>
      <vuln:product>cpe:/o:engardelinux:secure_community:1.0.1</vuln:product>
      <vuln:product>cpe:/o:engardelinux:secure_community:2.0</vuln:product>
      <vuln:product>cpe:/o:engardelinux:secure_linux:1.1::professional</vuln:product>
      <vuln:product>cpe:/o:engardelinux:secure_linux:1.2::professional</vuln:product>
      <vuln:product>cpe:/o:engardelinux:secure_linux:1.5::professional</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:8.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:current</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0962</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:23.193-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9415" name="oval:org.mitre.oval:def:9415"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U" xml:lang="en">20031202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000794" xml:lang="en">CLA-2003:794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107055681311602&amp;w=2" xml:lang="en">20031204 rsync security advisory (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107055684711629&amp;w=2" xml:lang="en">2003-0048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107055702911867&amp;w=2" xml:lang="en">20031204 [OpenPKG-SA-2003.051] OpenPKG Security Advisory (rsync)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107056923528423&amp;w=2" xml:lang="en">20031204 GLSA: exploitable heap overflow in rsync (200312-03)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/325603" xml:lang="en">VU#325603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:111" xml:lang="en">MDKSA-2003:111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-398.html" xml:lang="en">RHSA-2003:398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9153" xml:lang="en">9153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13899" xml:lang="en">linux-rsync-heap-overflow(13899)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0963">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:alexander_v._lukyanov:lftp:2.6.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.3</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.4.9</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.5.2</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.0</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.3</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.4</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.5</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.6</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.7</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.8</vuln:product>
      <vuln:product>cpe:/a:alexander_v._lukyanov:lftp:2.6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0963</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180" name="oval:org.mitre.oval:def:11180"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U" xml:lang="en">20040101-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107126386226196&amp;w=2" xml:lang="en">20031212 [slackware-security]  lftp security update (SSA:2003-346-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107152267121513&amp;w=2" xml:lang="en">20031213 lftp buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107167974714484&amp;w=2" xml:lang="en">20031217 [OpenPKG-SA-2003.053] OpenPKG Security Advisory (lftp)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107177409418121&amp;w=2" xml:lang="en">20031218 GLSA: lftp (200312-07)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107340499504411&amp;w=2" xml:lang="en">CLA-2004:800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-406" xml:lang="en">DSA-406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:116" xml:lang="en">MDKSA-2003:116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_051_lftp.html" xml:lang="en">SuSE-SA:2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-403.html" xml:lang="en">RHSA-2003:403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-404.html" xml:lang="en">RHSA-2003:404</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0964">
    <vuln:cve-id>CVE-2003-0964</vuln:cve-id>
    <vuln:published-datetime>2003-11-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:00.523-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: N/A. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0965">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0965</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A813" name="oval:org.mitre.oval:def:813"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" xml:lang="en">CLA-2004:842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mail.python.org/pipermail/mailman-announce/2003-December/000066.html" xml:lang="en">[Mailman-Announce] 20031231 RELEASED Mailman 2.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-436" xml:lang="en">DSA-436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:013" xml:lang="en">MDKSA-2004:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-020.html" xml:lang="en">RHSA-2004:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9336" xml:lang="en">9336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14121" xml:lang="en">mailman-admin-xss(14121)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0966">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:elm_development_group:elm:2.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:elm_development_group:elm:2.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0966</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:15.033-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=112078" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=112078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-009.html" xml:lang="en">RHSA-2004:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9430" xml:lang="en">9430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14840" xml:lang="en">elm-frm-subject-bo(14840)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the frm command in elm 2.5.6 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code via a long Subject line.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0967">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freeradius:freeradius:0.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freeradius:freeradius:0.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0967</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.543-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10917" name="oval:org.mitre.oval:def:10917"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106935911101493&amp;w=2" xml:lang="en">20031120 Remote DoS in FreeRADIUS, all versions.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106944220426970" xml:lang="en">20031121 FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.info/?l=freeradius-users&amp;m=106947389449613&amp;w=2" xml:lang="en">http://marc.info/?l=freeradius-users&amp;m=106947389449613&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-386.html" xml:lang="en">RHSA-2003:386</vuln:reference>
    </vuln:references>
    <vuln:summary>rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0968">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freeradius:freeradius:0.9.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-0968</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:36.300-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106986437621130&amp;w=2" xml:lang="en">20031126 FreeRADIUS &lt;= 0.9.3 rlm_smb module stack overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0969">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mpg321:mpg321:0.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mpg321:mpg321:0.2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0969</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:15.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-411" xml:lang="en">DSA-411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_02_tcpdump.html" xml:lang="en">SuSE-SA:2004:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9364" xml:lang="en">9364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14148" xml:lang="en">mpg321-mp3-format-string(14148)</vuln:reference>
    </vuln:references>
    <vuln:summary>mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0970">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:sun:sun_fire:b1600"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:sun:sun_fire:b1600</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0970</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:41.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57430" xml:lang="en">57430</vuln:reference>
    </vuln:references>
    <vuln:summary>The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0971">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.3b"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.3</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.3b</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.4</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.5</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.6</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.7</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0971</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10982" name="oval:org.mitre.oval:def:10982"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000798" xml:lang="en">CLA-2003:798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.html" xml:lang="en">http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.html" xml:lang="en">http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106995769213221&amp;w=2" xml:lang="en">20031127 GnuPG's ElGamal signing keys compromised</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-429" xml:lang="en">DSA-429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/940388" xml:lang="en">VU#940388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:109" xml:lang="en">MDKSA-2003:109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_048_gpg.html" xml:lang="en">SuSE-SA:2003:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-390.html" xml:lang="en">RHSA-2003:390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-395.html" xml:lang="en">RHSA-2003:395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9115" xml:lang="en">9115</vuln:reference>
    </vuln:references>
    <vuln:summary>GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0972">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:3.9.15"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:screen:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:screen:3.9.4</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:3.9.8</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:3.9.9</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:3.9.10</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:3.9.11</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:3.9.13</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:3.9.15</vuln:product>
      <vuln:product>cpe:/a:gnu:screen:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0972</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:38.770-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000809" xml:lang="en">CLA-2004:809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://groups.yahoo.com/group/gnu-screen/message/3118" xml:lang="en">http://groups.yahoo.com/group/gnu-screen/message/3118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106995837813873&amp;w=2" xml:lang="en">20031127 GNU screen buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-408" xml:lang="en">DSA-408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:113" xml:lang="en">MDKSA-2003:113</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0973">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:3.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:mod_python:2.7</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.2</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.3</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.4</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.5</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.6</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.7</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.8</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:3.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:3.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:3.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0973</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10259" name="oval:org.mitre.oval:def:10259"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A828" name="oval:org.mitre.oval:def:828"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A839" name="oval:org.mitre.oval:def:839"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://bugzilla.fedora.us/show_bug.cgi?id=1325" xml:lang="en">FEDORA-2004-1325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000837" xml:lang="en">CLA-2004:837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-452" xml:lang="en">DSA-452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.modpython.org/pipermail/mod_python/2003-November/004005.html" xml:lang="en">http://www.modpython.org/pipermail/mod_python/2003-November/004005.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-058.html" xml:lang="en">RHSA-2004:058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-063.html" xml:lang="en">RHSA-2004:063</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0974">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:applied_watch_technologies:applied_watch_command_center:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:applied_watch_technologies:applied_watch_command_center:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0974</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:39.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107004362416252&amp;w=2" xml:lang="en">20031128 Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107005523025918&amp;w=2" xml:lang="en">20031128 Applied Watch Response to Bugtraq.org post - Was: Multiple Remote Issues in Applied Watch IDS Suite</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107031196324376&amp;w=2" xml:lang="en">20031201 Re: Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugtraq.org/advisories/_BSSADV-0000.txt" xml:lang="en">http://www.bugtraq.org/advisories/_BSSADV-0000.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9124" xml:lang="en">9124</vuln:reference>
    </vuln:references>
    <vuln:summary>Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using addrule.c.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0975">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:1.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0975</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00042.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00042.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106917674428552&amp;w=2" xml:lang="en">20031118 Apple Safari 1.1 (v100)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/7973" xml:lang="en">mozilla-netscape-steal-cookies(7973)</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0976">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:6.5:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:novell:netware:6.5</vuln:product>
      <vuln:product>cpe:/o:novell:netware:6.5:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0976</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10089375.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10089375.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13915" xml:lang="en">netware-nfs-share-access(13915)</vuln:reference>
    </vuln:references>
    <vuln:summary>NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0977">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.8"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cvs:cvs:1.10.7</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.10.8</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.1</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.1_p1</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.2</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.3</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.4</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.5</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.6</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:8.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0977</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11528" name="oval:org.mitre.oval:def:11528"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A855" name="oval:org.mitre.oval:def:855"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A866" name="oval:org.mitre.oval:def:866"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&amp;JServSessionIdservlets=8u3x1myav1" xml:lang="en">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&amp;JServSessionIdservlets=8u3x1myav1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000808" xml:lang="en">CLA-2004:808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107168035515554&amp;w=2" xml:lang="en">20031217 [OpenPKG-SA-2003.052] OpenPKG Security Advisory (cvs)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107540163908129&amp;w=2" xml:lang="en">20040129 [FLSA-2004:1207] Updated cvs resolves security vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-422" xml:lang="en">DSA-422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:112" xml:lang="en">MDKSA-2003:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-003.html" xml:lang="en">RHSA-2004:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-004.html" xml:lang="en">RHSA-2004:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13929" xml:lang="en">cvs-module-file-manipulation(13929)</vuln:reference>
    </vuln:references>
    <vuln:summary>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0978">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.3</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0978</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107047470625214&amp;w=2" xml:lang="en">20031203 GnuPG 1.2.3, 1.3.3 external HKP interface format string issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_048_gpg.html" xml:lang="en">SuSE-SA:2003:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s-quadra.com/advisories/Adv-20031203.txt" xml:lang="en">http://www.s-quadra.com/advisories/Adv-20031203.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13892" xml:lang="en">gnupg-gpgkeyshkp-format-string(13892)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0979">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freescripts:visitorbook:le"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freescripts:visitorbook:le</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0979</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:44.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107107840622493&amp;w=2" xml:lang="en">20031210 Visitorbook LE Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" xml:lang="en">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0980">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freescripts:visitorbook:le"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freescripts:visitorbook:le</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0980</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:46.020-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107107840622493&amp;w=2" xml:lang="en">20031210 Visitorbook LE Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" xml:lang="en">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE (visitorbook.pl) allows remote attackers to inject arbitrary HTML or web script via (1) the "do" parameter, (2) via the "user" parameter from a host with a malicious reverse DNS name, (3) via quote marks or ampersands in other parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0981">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freescripts:visitorbook:le"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freescripts:visitorbook:le</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0981</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:47.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107107840622493&amp;w=2" xml:lang="en">20031210 Visitorbook LE Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" xml:lang="en">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0982">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:4.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:4.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4630"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4630:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4630:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4650"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4650:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4650:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_distribution_manager_4670"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:507"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:507_2.2_.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:507_3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:507_4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:507_4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:560"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:560_2.2_.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:560_3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:560_4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:560_4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:590"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:590_2.2_.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:590_3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:590_4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:590_4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:7320"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:7320_2.2_.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:7320_3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:7320_4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine:7320_4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine_module:for_cisco_router_2600_series"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine_module:for_cisco_router_3600_series"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:content_engine_module:for_cisco_router_3700_series"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:enterprise_content_delivery_network_software:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:enterprise_content_delivery_network_software:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:content_router_4430"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:content_router_4450"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:4.0.3</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:4.1.1</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:4.1.3</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:4.2</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:4.2.7</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:4.2.9</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:5.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software:5.0.3</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4630</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4630:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4630:4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4650</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4650:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4650:4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_distribution_manager_4670</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:507</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:507_2.2_.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:507_3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:507_4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:507_4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:560</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:560_2.2_.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:560_3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:560_4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:560_4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:590</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:590_2.2_.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:590_3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:590_4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:590_4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:7320</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:7320_2.2_.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:7320_3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:7320_4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine:7320_4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine_module:for_cisco_router_2600_series</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine_module:for_cisco_router_3600_series</vuln:product>
      <vuln:product>cpe:/a:cisco:content_engine_module:for_cisco_router_3700_series</vuln:product>
      <vuln:product>cpe:/a:cisco:enterprise_content_delivery_network_software:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:enterprise_content_delivery_network_software:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:content_router_4430</vuln:product>
      <vuln:product>cpe:/h:cisco:content_router_4450</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0982</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:18.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml" xml:lang="en">20031210 Vulnerability in Authentication Library for ACNS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/352462" xml:lang="en">VU#352462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9187" xml:lang="en">9187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13945" xml:lang="en">cisco-acns-password-bo(13945)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0983">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:80-7111-01_for_the_unity-svrx255-1a"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:80-7112-01_for_the_unity-svrx255-2a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:80-7111-01_for_the_unity-svrx255-1a</vuln:product>
      <vuln:product>cpe:/h:cisco:80-7112-01_for_the_unity-svrx255-2a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0983</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:19.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20031210-unity.shtml" xml:lang="en">20031210 Unity Vulnerabilities on IBM-based Servers</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0984">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0984</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1013" name="oval:org.mitre.oval:def:1013"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A859" name="oval:org.mitre.oval:def:859"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9406" name="oval:org.mitre.oval:def:9406"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000799" xml:lang="en">CLA-2004:799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107394143105081&amp;w=2" xml:lang="en">20040112 SmoothWall Project Security Advisory SWP-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html" xml:lang="en">ESA-20040105-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:001" xml:lang="en">MDKSA-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_049_kernel.html" xml:lang="en">SuSE-SA:2003:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00000.html" xml:lang="en">FEDORA-2003-046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-417.html" xml:lang="en">RHSA-2003:417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-188.html" xml:lang="en">RHSA-2004:188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9154" xml:lang="en">9154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008594" xml:lang="en">1008594</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13943" xml:lang="en">linux-rtc-memory-leak(13943)</vuln:reference>
    </vuln:references>
    <vuln:summary>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0985">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0985</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-05-02T21:29:23.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A860" name="oval:org.mitre.oval:def:860"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A867" name="oval:org.mitre.oval:def:867"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040102-01-U" xml:lang="en">20040102-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2004-01/0070.html" xml:lang="en">20040108 [slackware-security] Slackware 8.1 kernel security update (SSA:2004-008-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000799" xml:lang="en">CLA-2004:799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://download.immunix.org/ImmunixOS/7.3/updates/IMNX-2004-73-001-01" xml:lang="en">IMNX-2004-73-001-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0013-mremap.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0013-mremap.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremap" xml:lang="en">http://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremap</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107332754521495&amp;w=2" xml:lang="en">2004-0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107332782121916&amp;w=2" xml:lang="en">20040105 Linux kernel mremap vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107340358402129&amp;w=2" xml:lang="en">20040105 Linux kernel do_mremap() proof-of-concept exploit code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107340814409017&amp;w=2" xml:lang="en">20040106 Linux mremap bug correction</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107350348418373&amp;w=2" xml:lang="en">20040107 [slackware-security]  Kernel security update  (SSA:2004-006-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107394143105081&amp;w=2" xml:lang="en">20040112 SmoothWall Project Security Advisory SWP-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2005-0528?op=file&amp;rev=0&amp;sc=0" xml:lang="en">http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2005-0528?op=file&amp;rev=0&amp;sc=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-045.shtml" xml:lang="en">O-045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-413" xml:lang="en">DSA-413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-417" xml:lang="en">DSA-417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-427" xml:lang="en">DSA-427</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-439" xml:lang="en">DSA-439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-440" xml:lang="en">DSA-440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-450" xml:lang="en">DSA-450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-470" xml:lang="en">DSA-470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-475" xml:lang="en">DSA-475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/490620" xml:lang="en">VU#490620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html" xml:lang="en">ESA-20040105-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:001" xml:lang="en">MDKSA-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_03_linux_kernel.html" xml:lang="en">SuSE-SA:2004:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-416.html" xml:lang="en">RHSA-2003:416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-417.html" xml:lang="en">RHSA-2003:417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-418.html" xml:lang="en">RHSA-2003:418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-419.html" xml:lang="en">RHSA-2003:419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9356" xml:lang="en">9356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14135" xml:lang="en">linux-domremap-gain-privileges(14135)</vuln:reference>
    </vuln:references>
    <vuln:summary>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0986">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22:pre10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22:pre10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0986</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:16.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9707" name="oval:org.mitre.oval:def:9707"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@3fdd54b3u9Eq0Wny2Nn1HGfI3pofOQ" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@3fdd54b3u9Eq0Wny2Nn1HGfI3pofOQ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.6/cset@3ffcf122S7e3xPZCpibrXq6KRRjwqw" xml:lang="en">http://linux.bkbits.net:8080/linux-2.6/cset@3ffcf122S7e3xPZCpibrXq6KRRjwqw</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-017.html" xml:lang="en">RHSA-2004:017</vuln:reference>
    </vuln:references>
    <vuln:summary>Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0987">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0987</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:17.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100108" name="oval:org.mitre.oval:def:100108"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4416" name="oval:org.mitre.oval:def:4416"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108437852004207&amp;w=2" xml:lang="en">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-22.xml" xml:lang="en">GLSA-200405-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008920" xml:lang="en">1008920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" xml:lang="en">101555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" xml:lang="en">101841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" xml:lang="en">57628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html" xml:lang="en">http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html" xml:lang="en">http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046" xml:lang="en">MDKSA-2004:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-600.html" xml:lang="en">RHSA-2004:600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-816.html" xml:lang="en">RHSA-2005:816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9571" xml:lang="en">9571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" xml:lang="en">SSA:2004-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0027" xml:lang="en">2004-0027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15041" xml:lang="en">apache-moddigest-response-replay(15041)</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0988">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:3.1.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0988</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:15.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A858" name="oval:org.mitre.oval:def:858"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A865" name="oval:org.mitre.oval:def:865"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000810" xml:lang="en">CLA-2004:810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107412130407906&amp;w=2" xml:lang="en">20040114 KDE Security Advisory: VCF file information reader vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200404-02.xml" xml:lang="en">GLSA-200404-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/820798" xml:lang="en">VU#820798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20040114-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20040114-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:003" xml:lang="en">MDKSA-2004:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-005.html" xml:lang="en">RHSA-2004:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-006.html" xml:lang="en">RHSA-2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9419" xml:lang="en">9419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14833" xml:lang="en">kde-kdepim-bo(14833)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0989">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:tcpdump:3.8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0989</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:38.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10599" name="oval:org.mitre.oval:def:10599"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A847" name="oval:org.mitre.oval:def:847"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A852" name="oval:org.mitre.oval:def:852"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" xml:lang="en">CSSA-2004-008.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" xml:lang="en">SCOSA-2004.9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/66445/" xml:lang="en">2004-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/66805/" xml:lang="en">ESA-20040119-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107577418225627&amp;w=2" xml:lang="en">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-425" xml:lang="en">DSA-425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/738518" xml:lang="en">VU#738518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" xml:lang="en">MDKSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" xml:lang="en">FEDORA-2004-090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" xml:lang="en">FEDORA-2004-092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" xml:lang="en">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" xml:lang="en">FLSA:1222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-007.html" xml:lang="en">RHSA-2004:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-008.html" xml:lang="en">RHSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/350238/30/21640/threaded" xml:lang="en">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9507" xml:lang="en">9507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008716" xml:lang="en">1008716</vuln:reference>
    </vuln:references>
    <vuln:summary>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0990">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:gpg_plugin:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-0990</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107247236124180&amp;w=2" xml:lang="en">20031224 Bugtraq Security Systems ADV-0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugtraq.org/advisories/_BSSADV-0001.txt" xml:lang="en">http://www.bugtraq.org/advisories/_BSSADV-0001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348366" xml:lang="en">20031226 Re: Reported Command Injection in Squirrelmail GPG</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9296" xml:lang="en">9296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14079" xml:lang="en">squirrelmail-parseaddress-command-execution(14079)</vuln:reference>
    </vuln:references>
    <vuln:summary>The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0991">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:1.0</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:1.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0:beta3</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0:beta4</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0:beta5</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.2</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.3</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.4</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.5</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.6</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.7</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.8</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.9</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.10</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.11</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.12</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.13</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0991</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:15.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" xml:lang="en">CLA-2004:842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mail.python.org/pipermail/mailman-announce/2004-February/000067.html" xml:lang="en">[Mailman-Announce] 20040208 RELEASED: Mailman 2.0.14 patch-only release</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-436" xml:lang="en">DSA-436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:013" xml:lang="en">MDKSA-2004:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-019.html" xml:lang="en">RHSA-2004:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9620" xml:lang="en">9620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15106" xml:lang="en">mailman-command-handler-dos(15106)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0992">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0992</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:17.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A815" name="oval:org.mitre.oval:def:815"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" xml:lang="en">CLA-2004:842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html" xml:lang="en">http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:013" xml:lang="en">MDKSA-2004:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-020.html" xml:lang="en">RHSA-2004:020</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0993">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.7::dev</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.14</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0993</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:15.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100111" name="oval:org.mitre.oval:def:100111"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4670" name="oval:org.mitre.oval:def:4670"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046" xml:lang="en">MDKSA-2004:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.apache.org/bugzilla/show_bug.cgi?id=23850" xml:lang="en">http://issues.apache.org/bugzilla/show_bug.cgi?id=23850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=apache-cvs&amp;m=107869603013722" xml:lang="en">[apache-cvs] 20040307 cvs commit: apache-1.3/src/modules/standard mod_access.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108437852004207&amp;w=2" xml:lang="en">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-22.xml" xml:lang="en">GLSA-200405-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" xml:lang="en">101555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" xml:lang="en">101841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" xml:lang="en">57628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apacheweek.com/features/security-13" xml:lang="en">http://www.apacheweek.com/features/security-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9829" xml:lang="en">9829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" xml:lang="en">SSA:2004-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0027" xml:lang="en">2004-0027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15422" xml:lang="en">apache-modaccess-obtain-information(15422)</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0994">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2.1::ms_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2001::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2002::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2003::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2004::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:v3.0::handhelds"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2001::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2002::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2003::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2004::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:windows_liveupdate:1.70.x"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:windows_liveupdate:1.90.x"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2.1::ms_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2001</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2001::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2002</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2002::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2003</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2003::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2004::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:v3.0::handhelds</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2001</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2001::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2002</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2002::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2003</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2003::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2004</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2004::pro</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2001</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2002</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2003</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2004</vuln:product>
      <vuln:product>cpe:/a:symantec:windows_liveupdate:1.70.x</vuln:product>
      <vuln:product>cpe:/a:symantec:windows_liveupdate:1.90.x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0994</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:57.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015510.html" xml:lang="en">20040112 SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107393473928245&amp;w=2" xml:lang="en">20040112 Re:   SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.biz/research/SRT2004-01-09-1022.txt" xml:lang="en">http://www.secnetops.biz/research/SRT2004-01-09-1022.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0995">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0995</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039" xml:lang="en">MS03-039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13131" xml:lang="en">win2k-message-queue-bo(13131)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0996">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control_host:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:unicenter_remote_control_host:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0996</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:45.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.ca.com/techbases/rp/urc6x-secnote.html" xml:lang="en">http://support.ca.com/techbases/rp/urc6x-secnote.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown "System Security Vulnerability" in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to gain privileges via the help interface.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0997">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control_host:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:unicenter_remote_control_host:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0997</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:45.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.ca.com/techbases/rp/urc6x-secnote.html" xml:lang="en">http://support.ca.com/techbases/rp/urc6x-secnote.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown "Denial of Service Attack" vulnerability in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to cause a denial of service (CPU consumption in URC host service).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0998">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:controlit:5.0::advanced"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:controlit:5.0::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:controlit:5.1::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control_option:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control_option:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control_option:5.1:::de"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:controlit:5.0::advanced</vuln:product>
      <vuln:product>cpe:/a:ca:controlit:5.0::enterprise</vuln:product>
      <vuln:product>cpe:/a:ca:controlit:5.1::enterprise</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control:5.2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control:6.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control_option:5.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control_option:5.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control_option:5.1:::de</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0998</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:46.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.ca.com/techbases/rp/urc5x-secnote.html" xml:lang="en">http://support.ca.com/techbases/rp/urc5x-secnote.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown "potential system security vulnerability" in Computer Associates (CA) Unicenter Remote Control 5.0 through 5.2, and ControlIT 5.0 and 5.1, may allow attackers to gain privileges to the local system account.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0999">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0999</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4098" name="oval:org.mitre.oval:def:4098"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57451" xml:lang="en">57451</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1000">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xchat:xchat:2.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xchat:xchat:2.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1000</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:38:59.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html" xml:lang="en">http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107152093419276&amp;w=2" xml:lang="en">20031214 GLSA: Malformed dcc send requests in xchat-2.0.6 lead to a denial of service</vuln:reference>
    </vuln:references>
    <vuln:summary>xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-x6380-nam:2.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-x6380-nam:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-x6380-nam:2.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-x6380-nam:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:5.4%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:7.5%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:7.6%281%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:catalyst_6500</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-x6380-nam:2.1%282%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-x6380-nam:2.1%282%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.2</vuln:product>
      <vuln:product>cpe:/o:cisco:catos:5.4%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:catos:7.5%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:catos:7.6%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1001</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:24.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml" xml:lang="en">20031215 Cisco FWSM Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-x6380-nam:2.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-x6380-nam:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-x6380-nam:2.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-x6380-nam:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:5.4%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:7.5%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:7.6%281%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:catalyst_6500</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-x6380-nam:2.1%282%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-x6380-nam:2.1%282%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.2</vuln:product>
      <vuln:product>cpe:/o:cisco:catos:5.4%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:catos:7.5%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:catos:7.6%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1002</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:24.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml" xml:lang="en">20031215 Cisco FWSM Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:pix_firewall:6.2.2_.111"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.1%284%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.1%284.206%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%283.210%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%285%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%286%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%287%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%289%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%281.200%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%284%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%284.101%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%284%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%285%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%283.100%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.3%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.3%283.102%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:pix_firewall:6.2.2_.111</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.1%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.1%284.206%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%283.210%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%285%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%286%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%287%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%289%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%281.200%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%284.101%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%285%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%283.100%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.3%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.3%283.102%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1003</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:18.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtml" xml:lang="en">20031215 Cisco PIX Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:pix_firewall:6.2.2_.111"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%283.100%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:pix_firewall:6.2.2_.111</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%283.100%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1004</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:18.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtml" xml:lang="en">20031215 Cisco PIX Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1005</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:24.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T14:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Dec/msg00001.html" xml:lang="en">APPLE-SA-2003-12-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3704" xml:lang="en">ESB-2003.0867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9266" xml:lang="en">9266</vuln:reference>
    </vuln:references>
    <vuln:summary>The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1006</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/878526" xml:lang="en">VU#878526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/347578" xml:lang="en">20031215 Buffer overflow/privilege escalation in MacOS X</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/347707" xml:lang="en">20031216 Re: Buffer overflow/privilege escalation in MacOS X</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348097" xml:lang="en">20031219 Re: Buffer overflow/privilege escalation in MacOS X - hfs.util also</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9228" xml:lang="en">9228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13995" xml:lang="en">macos-cd9660-bo(13995)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1007</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008532" xml:lang="en">1008532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9264" xml:lang="en">9264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14051" xml:lang="en">applefileserver-dos(14051)</vuln:reference>
    </vuln:references>
    <vuln:summary>AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1008</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14195" xml:lang="en">macos-screen-saver-bypass(14195)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1009</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=32478" xml:lang="en">http://docs.info.apple.com/article.html?artnum=32478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.carrel.org/dhcp-vuln.html" xml:lang="en">http://www.carrel.org/dhcp-vuln.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9110" xml:lang="en">9110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13874" xml:lang="en">macos-dhcp-gain-privileges(13874)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1010</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9265" xml:lang="en">9265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14193" xml:lang="en">macos-fsusage-gain-privileges(14193)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in fs_usage in Mac OS X 10.2.8 and 10.3.2 and Mac OS X Server 10.2.8 and 10.3.2 allows local users to gain privileges via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1011</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343087" xml:lang="en">20031031 Console Root On OSX up to 10.2.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8945" xml:lang="en">8945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13573" xml:lang="en">macos-ctrlc-gain-access(13573)</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1012</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:17.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10202" name="oval:org.mitre.oval:def:10202"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A856" name="oval:org.mitre.oval:def:856"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000801" xml:lang="en">CLA-2004:801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-407" xml:lang="en">DSA-407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00012.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00012.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:002" xml:lang="en">MDKSA-2004:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-001.html" xml:lang="en">RHSA-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-002.html" xml:lang="en">RHSA-2004:002</vuln:reference>
    </vuln:references>
    <vuln:summary>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1013</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:17.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10097" name="oval:org.mitre.oval:def:10097"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A857" name="oval:org.mitre.oval:def:857"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000801" xml:lang="en">CLA-2004:801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-407" xml:lang="en">DSA-407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00012.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00012.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:002" xml:lang="en">MDKSA-2004:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-001.html" xml:lang="en">RHSA-2004:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-002.html" xml:lang="en">RHSA-2004:002</vuln:reference>
    </vuln:references>
    <vuln:summary>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1014</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:39.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109517732328759&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME field multiple occurrence issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/17333" xml:lang="en">mime-field-filtering-bypass(17333)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use multiple MIME fields with the same name, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1015</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109525252118936&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME field whitespace issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/9273" xml:lang="en">mime-tools-incorrect-concatenation(9273)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1016</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109521027007616&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME field quoting issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/17336" xml:lang="en">mime-quote-filtering-bypass(17336)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:macromedia:director:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:4.0_r12"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:5.0_r50"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.29.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.40.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.47.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.65.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.79.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macromedia:director:5.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:4.0_r12</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:5.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:5.0_r50</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.29.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.40.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.47.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.65.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.79.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1017</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html" xml:lang="en">http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8900" xml:lang="en">8900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14013" xml:lang="en">flash-file-predictable-location(14013)</vuln:reference>
    </vuln:references>
    <vuln:summary>Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read restricted files via vulnerabilities in web browsers whose exploits rely on predictable names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1018</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9254" xml:lang="en">9254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IBM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-20" xml:lang="en">MSS-OAR-E01-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14037" xml:lang="en">aix-enq-format-string(14037)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:irssi:irssi:0.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:irssi:irssi:0.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:irssi:irssi:0.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:irssi:irssi:0.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:irssi:irssi:0.8.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:irssi:irssi:0.8.4</vuln:product>
      <vuln:product>cpe:/a:irssi:irssi:0.8.5</vuln:product>
      <vuln:product>cpe:/a:irssi:irssi:0.8.6</vuln:product>
      <vuln:product>cpe:/a:irssi:irssi:0.8.7</vuln:product>
      <vuln:product>cpe:/a:irssi:irssi:0.8.8</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.2</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1020</vuln:cve-id>
    <vuln:published-datetime>2004-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:117" xml:lang="en">MDKSA-2003:117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/347218" xml:lang="en">20031211 irssi - potential remote crash</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13973" xml:lang="en">irssi-dos(13973)</vuln:reference>
    </vuln:references>
    <vuln:summary>The format_send_to_gui function in formats.c for irssi before 0.8.9 allows remote IRC users to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6a"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1021</vuln:cve-id>
    <vuln:published-datetime>2005-01-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.5/SCOSA-2005.5.txt" xml:lang="en">SCOSA-2005.5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/972598" xml:lang="en">VU#972598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12372" xml:lang="en">12372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/19479" xml:lang="en">openserver-scosession-gain-privilege(19479)</vuln:reference>
    </vuln:references>
    <vuln:summary>The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:debian:fsp:2.81.b18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:fsp:2.81.b18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1022</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-09T21:30:15.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-048.shtml" xml:lang="en">O-048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-416" xml:lang="en">DSA-416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9377" xml:lang="en">9377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14154" xml:lang="en">fspsuite-dot-directory-traversal(14154)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:midnight_commander:midnight_commander:4.5.52"/>
        <cpe-lang:fact-ref name="cpe:/a:midnight_commander:midnight_commander:4.5.55"/>
        <cpe-lang:fact-ref name="cpe:/a:midnight_commander:midnight_commander:4.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:midnight_commander:midnight_commander:4.5.52</vuln:product>
      <vuln:product>cpe:/a:midnight_commander:midnight_commander:4.5.55</vuln:product>
      <vuln:product>cpe:/a:midnight_commander:midnight_commander:4.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1023</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:17.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A822" name="oval:org.mitre.oval:def:822"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt" xml:lang="en">CSSA-2004-014.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2003/09/msg00309.html" xml:lang="en">20030919 uninitialized buffer in midnight commander</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000833" xml:lang="en">CLA-2004:833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA-2004-058.shtml" xml:lang="en">FEDORA-2004-058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108118433222764&amp;w=2" xml:lang="en">20040405 [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-034.html" xml:lang="en">RHSA-2004:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-035.html" xml:lang="en">RHSA-2004:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-09.xml" xml:lang="en">GLSA-200403-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-424" xml:lang="en">DSA-424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:007" xml:lang="en">MDKSA-2004:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2004-May/msg00002.html" xml:lang="en">FLSA:1224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8658" xml:lang="en">8658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13247" xml:lang="en">midnight-commander-vfssresolvesymlink-bo(13247)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1024</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1528" name="oval:org.mitre.oval:def:1528"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57455" xml:lang="en">57455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/281356" xml:lang="en">VU#281356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9280" xml:lang="en">9280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14065" xml:lang="en">solaris-lsf-gain-privileges(14065)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1025</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:42.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A490" name="oval:org.mitre.oval:def:490"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A491" name="oval:org.mitre.oval:def:491"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A510" name="oval:org.mitre.oval:def:510"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A511" name="oval:org.mitre.oval:def:511"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A512" name="oval:org.mitre.oval:def:512"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A513" name="oval:org.mitre.oval:def:513"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A526" name="oval:org.mitre.oval:def:526"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/652278" xml:lang="en">VU#652278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/346948" xml:lang="en">20031209 Internet Explorer URL parsing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-033A.html" xml:lang="en">TA04-033A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zapthedingbat.com/security/ex01/vun1.htm" xml:lang="en">http://www.zapthedingbat.com/security/ex01/vun1.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004" xml:lang="en">MS04-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13935" xml:lang="en">ie-domain-url-spoofing(13935)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1026</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:43.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630" name="oval:org.mitre.oval:def:630"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643" name="oval:org.mitre.oval:def:643"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687" name="oval:org.mitre.oval:def:687"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689" name="oval:org.mitre.oval:def:689"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745" name="oval:org.mitre.oval:def:745"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774" name="oval:org.mitre.oval:def:774"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805" name="oval:org.mitre.oval:def:805"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106979349517578&amp;w=2" xml:lang="en">20031125 BackToFramedJpu - a successor of BackToJpu attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107038202225587&amp;w=2" xml:lang="en">20031201 Comments on 5 IE vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/784102" xml:lang="en">VU#784102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-033A.html" xml:lang="en">TA04-033A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004" xml:lang="en">MS04-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13846" xml:lang="en">ie-subframe-xss(13846)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1027</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:45.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A527" name="oval:org.mitre.oval:def:527"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A529" name="oval:org.mitre.oval:def:529"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A530" name="oval:org.mitre.oval:def:530"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A531" name="oval:org.mitre.oval:def:531"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A532" name="oval:org.mitre.oval:def:532"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A534" name="oval:org.mitre.oval:def:534"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A629" name="oval:org.mitre.oval:def:629"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106979479719446&amp;w=2" xml:lang="en">20031125 HijackClickV2 - a successor of HijackClick attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107038202225587&amp;w=2" xml:lang="en">20031201 Comments on 5 IE vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/413886" xml:lang="en">VU#413886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006036" xml:lang="en">1006036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-033A.html" xml:lang="en">TA04-033A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004" xml:lang="en">MS04-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13844" xml:lang="en">ie-method-perform-actions(13844)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1028</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106979428718705&amp;w=2" xml:lang="en">20031125 Note for "Invalid ContentType may disclose cache directory"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106979624321665&amp;w=2" xml:lang="en">20031125 Invalid ContentType may disclose cache directory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107038202225587&amp;w=2" xml:lang="en">20031201 Comments on 5 IE vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.safecenter.net/UMBRELLAWEBV4/threadid10008" xml:lang="en">http://www.safecenter.net/UMBRELLAWEBV4/threadid10008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13847" xml:lang="en">ie-download-directory-disclosure(13847)</vuln:reference>
    </vuln:references>
    <vuln:summary>The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.4</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.3</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1029</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:44.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/66805/" xml:lang="en">ESA-20040119-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107193841728533&amp;w=2" xml:lang="en">20031220 Remote crash in tcpdump from OpenBSD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107213553214985&amp;w=2" xml:lang="en">20031221 Re: Remote crash in tcpdump from OpenBSD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=tcpdump-workers&amp;m=107228187124962&amp;w=2" xml:lang="en">[tcpdump-workers] 20031224 Seg fault of tcpdump (v 3.8.1 and below) with malformed l2tp packets</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-425" xml:lang="en">DSA-425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" xml:lang="en">MDKSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/350238/30/21640/threaded" xml:lang="en">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008748" xml:lang="en">1008748</vuln:reference>
    </vuln:references>
    <vuln:summary>The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dameware_development:mini_remote_control_server:3.70_.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dameware_development:mini_remote_control_server:3.71_.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dameware_development:mini_remote_control_server:3.72_.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dameware_development:mini_remote_control_server:3.70_.0.0</vuln:product>
      <vuln:product>cpe:/a:dameware_development:mini_remote_control_server:3.71_.0.0</vuln:product>
      <vuln:product>cpe:/a:dameware_development:mini_remote_control_server:3.72_.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1030</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107152094119279&amp;w=2" xml:lang="en">20031214 DameWare Mini Remote Control Server &lt;= 3.72 Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107187110617266&amp;w=2" xml:lang="en">20031219 [Exploit]: DameWare Mini Remote Control Server Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107392603615840&amp;w=2" xml:lang="en">20040110 DameWare Mini Remote Control &lt; v3.73 remote exploit by kralor]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sh0dan.org/files/dwmrcs372.txt" xml:lang="en">http://sh0dan.org/files/dwmrcs372.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/909678" xml:lang="en">VU#909678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9213" xml:lang="en">9213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14001" xml:lang="en">dameware-spoof-packet-bo(14001)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0_beta_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1031</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:51.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0078.html" xml:lang="en">20030808 VBulletin New Member XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pi3:pi3web:2.0.2_beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pi3:pi3web:2.0.2_beta_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1032</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-12-19T21:59:00.227-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105465813729100&amp;w=2" xml:lang="en">20030602 Tripbit Advisory TA-2003-05 Buffer Overflow Vulnerability in Pi3 Web</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105484265218325&amp;w=2" xml:lang="en">20030605 Re: Tripbit Advisory TA-2003-05 Buffer Overflow Vulnerability in Pi3 Web</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006913" xml:lang="en">1006913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7787" xml:lang="en">7787</vuln:reference>
    </vuln:references>
    <vuln:summary>Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_db:7.3.00</vuln:product>
      <vuln:product>cpe:/a:sap:sap_db:7.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1033</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html" xml:lang="en">[SAP DB Dev] 20030422 Security Alert: Development Tools</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105103613727471&amp;w=2" xml:lang="en">20030422 SRT2003-04-22-1336 - SAP DB Development Tools install flaw</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7407" xml:lang="en">7407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7408" xml:lang="en">7408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11842" xml:lang="en">sap-db-gain-privileges(11842)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_db:7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1034</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104914778303805&amp;w=2" xml:lang="en">20030331 SRT2003-03-31-1219 - SAP world writable server binaries</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7242" xml:lang="en">7242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11669" xml:lang="en">sap-db-world-writable(11669)</vuln:reference>
    </vuln:references>
    <vuln:summary>The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:sap_r_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:sapgui:4.6c::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:sapgui:4.6d::windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:sap_r_3</vuln:product>
      <vuln:product>cpe:/a:sap:sapgui:4.6c::windows</vuln:product>
      <vuln:product>cpe:/a:sap:sapgui:4.6d::windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1035</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:45.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004039.html" xml:lang="en">20030304 SAP R/3, account locking and RFC SDK</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/451378/100/0/threaded" xml:lang="en">20061112 Old SAP exploits</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7007" xml:lang="en">7007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11487" xml:lang="en">sap-sapinfo-lockout-bypass(11487)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:4.6_pl463"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:6.10_pl30"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:6.20_pl7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:internet_transaction_server:4.6_pl463</vuln:product>
      <vuln:product>cpe:/a:sap:internet_transaction_server:6.10_pl30</vuln:product>
      <vuln:product>cpe:/a:sap:internet_transaction_server:6.20_pl7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1036</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" xml:lang="en">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14186" xml:lang="en">sap-multiple-bo(14186)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session parameters, or (4) a long HTTP Content-Type header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:4.6_pl463"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:6.10_pl30"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:6.20_pl7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:internet_transaction_server:4.6_pl463</vuln:product>
      <vuln:product>cpe:/a:sap:internet_transaction_server:6.10_pl30</vuln:product>
      <vuln:product>cpe:/a:sap:internet_transaction_server:6.20_pl7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1037</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:40.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009453" xml:lang="en">1009453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" xml:lang="en">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15514" xml:lang="en">sap-wgate-format-string(15514)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:4.6_pl463"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:6.10_pl30"/>
        <cpe-lang:fact-ref name="cpe:/a:sap:internet_transaction_server:6.20_pl7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:internet_transaction_server:4.6_pl463</vuln:product>
      <vuln:product>cpe:/a:sap:internet_transaction_server:6.10_pl30</vuln:product>
      <vuln:product>cpe:/a:sap:internet_transaction_server:6.20_pl7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1038</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" xml:lang="en">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15516" xml:lang="en">sap-agate-path-disclosure(15516)</vuln:reference>
    </vuln:references>
    <vuln:summary>The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list of installed DLLs and full pathnames.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sap:mysap_business_suite"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sap:mysap_business_suite</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1039</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" xml:lang="en">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15513" xml:lang="en">mysap-host-header-bo(15513)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Application Server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1040</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-08-13T17:47:19.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9423" name="oval:org.mitre.oval:def:9423"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040204-01-U.asc" xml:lang="en">20040204-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" xml:lang="en">CLSA-2004:820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_049_kernel.html" xml:lang="en">SuSE-SA:2003:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-065.html" xml:lang="en">RHSA-2004:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-069.html" xml:lang="en">RHSA-2004:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-106.html" xml:lang="en">RHSA-2004:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-188.html" xml:lang="en">RHSA-2004:188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15577" xml:lang="en">linux-kmod-signals-dos(15577)</vuln:reference>
    </vuln:references>
    <vuln:summary>kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1041</vuln:cve-id>
    <vuln:published-datetime>2004-06-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:48.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1186" name="oval:org.mitre.oval:def:1186"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1943" name="oval:org.mitre.oval:def:1943"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3514" name="oval:org.mitre.oval:def:3514"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A956" name="oval:org.mitre.oval:def:956"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/187196" xml:lang="en">VU#187196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348521" xml:lang="en">20031230 IE 5.x-6.0 allows executing arbitrary programs using showHelp()</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9320" xml:lang="en">9320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" xml:lang="en">TA04-196A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023" xml:lang="en">MS04-023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14105" xml:lang="en">ie-showhelp-directory-traversal(14105)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1042</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=214290" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=214290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" xml:lang="en">CLA-2003:774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343185" xml:lang="en">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8953" xml:lang="en">8953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13594" xml:lang="en">bugzilla-productname-sql-injection(13594)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1043</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=219044" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=219044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" xml:lang="en">CLA-2003:774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343185" xml:lang="en">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8953" xml:lang="en">8953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13596" xml:lang="en">bugzilla-url-sql-injection(13596)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1044</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=219690" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=219690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" xml:lang="en">CLA-2003:774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343185" xml:lang="en">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8953" xml:lang="en">8953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13597" xml:lang="en">bugzilla-groupid-gain-privileges(13597)</vuln:reference>
    </vuln:references>
    <vuln:summary>editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1045</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=209376" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=209376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" xml:lang="en">CLA-2003:774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343185" xml:lang="en">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8953" xml:lang="en">8953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13600" xml:lang="en">bugzilla-obtain-information(13600)</vuln:reference>
    </vuln:references>
    <vuln:summary>votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1046</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=209742" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=209742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343185" xml:lang="en">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8953" xml:lang="en">8953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13602" xml:lang="en">bugzilla-describecomponents-obtain-info(13602)</vuln:reference>
    </vuln:references>
    <vuln:summary>describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1047">
    <vuln:cve-id>CVE-2003-1047</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:37.147-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0540.  Reason: This candidate is a duplicate of CVE-2004-0540.  Notes: All CVE users should reference CVE-2004-0540 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1048</vuln:cve-id>
    <vuln:published-datetime>2004-07-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:49.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1793" name="oval:org.mitre.oval:def:1793"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A206" name="oval:org.mitre.oval:def:206"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2100" name="oval:org.mitre.oval:def:2100"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A212" name="oval:org.mitre.oval:def:212"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A236" name="oval:org.mitre.oval:def:236"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A509" name="oval:org.mitre.oval:def:509"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A517" name="oval:org.mitre.oval:def:517"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009445.html" xml:lang="en">20030902 New Microsoft Internet Explorer mshtml.dll Denial of Service?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009473.html" xml:lang="en">20040902 AW: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009506.html" xml:lang="en">20040903 Re: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll Denial of Service?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-191.shtml" xml:lang="en">O-191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/685364" xml:lang="en">VU#685364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8530" xml:lang="en">8530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-212A.html" xml:lang="en">TA04-212A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-025" xml:lang="en">MS04-025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16804" xml:lang="en">ie-mshtml-gif-bo(16804)</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.0::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.0::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.0::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1049</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9243" xml:lang="en">9243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY44841&amp;apar=only" xml:lang="en">IY44841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY44842&amp;apar=only" xml:lang="en">IY44842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14030" xml:lang="en">db2-dms-insecure-permissions(14030)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1050</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343804" xml:lang="en">20031108 SRT2003-11-06-0710 - IBM DB2 Multiple local security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8990" xml:lang="en">8990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13633" xml:lang="en">db2-multiple-binaries-bo(13633)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1051</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343804" xml:lang="en">20031108 SRT2003-11-06-0710 - IBM DB2 Multiple local security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8989" xml:lang="en">8989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13633" xml:lang="en">db2-multiple-binaries-bo(13633)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:7.2::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1::aix"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.2::windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2:9.0</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:6.0</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.0::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.1::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:7.2::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.0::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1::aix</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.2::windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1052</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/331904" xml:lang="en">20030805 Slight privilege elevation from bin to root in IBM DB2 7.1 - 8.1 all binaries</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8346" xml:lang="en">8346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12826" xml:lang="en">ibm-db2-gain-privileges(12826)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xshisen:xshisen:1.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xshisen:xshisen:1.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1053</vuln:cve-id>
    <vuln:published-datetime>2003-10-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:41.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=213957" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=213957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8770" xml:lang="en">8770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8776" xml:lang="en">8776</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" xml:lang="en">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13358" xml:lang="en">xshisen-kconv-bo(13358)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13359" xml:lang="en">xshisen-xshisenlib-bo(13359)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mod_access_referer:mod_access_referer:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_access_referer:mod_access_referer:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1054</vuln:cve-id>
    <vuln:published-datetime>2003-04-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:35:55.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T13:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004555.html" xml:lang="en">20030416 [VulnWatch] Apache mod_access_referer denial of service issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=151905" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=151905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7375" xml:lang="en">7375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html" xml:lang="en">http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1055</vuln:cve-id>
    <vuln:published-datetime>2003-07-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52222-1" xml:lang="en">52222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3224" xml:lang="en">ESB-2003.0461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-113.shtml" xml:lang="en">N-113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7064" xml:lang="en">7064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006401" xml:lang="en">1006401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11641" xml:lang="en">solaris-nssldapso1-bo(11641)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1056</vuln:cve-id>
    <vuln:published-datetime>2003-12-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57443-1" xml:lang="en">57443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3688" xml:lang="en">ESB-2003.0851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9199" xml:lang="en">9199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13952" xml:lang="en">solaris-ed1-tmpfile-insecure(13952)</vuln:reference>
    </vuln:references>
    <vuln:summary>The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1057</vuln:cve-id>
    <vuln:published-datetime>2003-12-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57441-1" xml:lang="en">57441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3675" xml:lang="en">ESB-2003.0844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-035.shtml" xml:lang="en">O-035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9170" xml:lang="en">9170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13914" xml:lang="en">cde-dtprintinfo-gain-privileges(13914)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1058</vuln:cve-id>
    <vuln:published-datetime>2003-12-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57419-1" xml:lang="en">57419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-033.shtml" xml:lang="en">O-033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9147" xml:lang="en">9147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13890" xml:lang="en">solaris-xsun-gain-privileges(13890)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1059</vuln:cve-id>
    <vuln:published-datetime>2003-11-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57360-1" xml:lang="en">57360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-029.shtml" xml:lang="en">O-029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9076" xml:lang="en">9076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13792" xml:lang="en">solaris-pgx32-gain-privileges(13792)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1060</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57406-1" xml:lang="en">57406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8929" xml:lang="en">8929</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13547" xml:lang="en">solaris-nfs-ufs-dos(13547)</vuln:reference>
    </vuln:references>
    <vuln:summary>The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1061</vuln:cve-id>
    <vuln:published-datetime>2003-10-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57080-1" xml:lang="en">57080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8836" xml:lang="en">8836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13434" xml:lang="en">solaris-race-dos(13434)</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1062</vuln:cve-id>
    <vuln:published-datetime>2003-10-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57340-1" xml:lang="en">57340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8831" xml:lang="en">8831</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13435" xml:lang="en">solaris-sysinfo-read-memory(13435)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1063</vuln:cve-id>
    <vuln:published-datetime>2003-08-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56300-1" xml:lang="en">56300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-134.shtml" xml:lang="en">N-134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8461" xml:lang="en">8461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12942" xml:lang="en">solaris-cachefs-inetdconf-overwrite(12942)</vuln:reference>
    </vuln:references>
    <vuln:summary>The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1064</vuln:cve-id>
    <vuln:published-datetime>2003-07-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55301-1" xml:lang="en">55301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/370060" xml:lang="en">VU#370060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8250" xml:lang="en">8250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12680" xml:lang="en">solaris-ipv6-packet-dos(12680)</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris 8 with IPv6 enabled allows remote attackers to cause a denial of service (kernel panic) via a crafted IPv6 packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1065</vuln:cve-id>
    <vuln:published-datetime>2003-07-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55340-1" xml:lang="en">55340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8253" xml:lang="en">8253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/19437" xml:lang="en">automountd-dos(19437)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/19441" xml:lang="en">openssh-ldap-dos(19441)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow local users to cause a denial of service (automountd crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1066</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55440-1" xml:lang="en">55440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/324015" xml:lang="en">20030604 Solaris syslogd overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7820" xml:lang="en">7820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12194" xml:lang="en">sun-syslogd-bo(12194)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1067</vuln:cve-id>
    <vuln:published-datetime>2003-06-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55420-1" xml:lang="en">55420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-108.shtml" xml:lang="en">N-108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/64758" xml:lang="en">64758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7991" xml:lang="en">7991</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12379" xml:lang="en">sun-database-functions-bo(12379)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1068</vuln:cve-id>
    <vuln:published-datetime>2003-06-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55260-1" xml:lang="en">55260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-105.shtml" xml:lang="en">N-105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7835" xml:lang="en">7835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11083" xml:lang="en">solaris-utmp-update-bo(11083)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1069</vuln:cve-id>
    <vuln:published-datetime>2003-06-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54181-1" xml:lang="en">54181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7794" xml:lang="en">7794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12140" xml:lang="en">sun-intelnetd-dos(12140)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1070</vuln:cve-id>
    <vuln:published-datetime>2003-04-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50922-1" xml:lang="en">50922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7455" xml:lang="en">7455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11906" xml:lang="en">sun-rpcbind-dos(11906)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1071</vuln:cve-id>
    <vuln:published-datetime>2003-01-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51980-1" xml:lang="en">51980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/944241" xml:lang="en">VU#944241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305105" xml:lang="en">20030103 Solaris 2.x /usr/sbin/wall Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6509" xml:lang="en">6509</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005882" xml:lang="en">1005882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006682" xml:lang="en">1006682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11608" xml:lang="en">solaris-wall-message-spoofing(11608)</vuln:reference>
    </vuln:references>
    <vuln:summary>rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1072</vuln:cve-id>
    <vuln:published-datetime>2003-04-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54100-1" xml:lang="en">54100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7454" xml:lang="en">7454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11895" xml:lang="en">sun-lofiadm-dos(11895)</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1073</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0044.html" xml:lang="en">20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0008-sun-at.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0008-sun-at.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50161-1" xml:lang="en">50161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-070.shtml" xml:lang="en">N-070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308577" xml:lang="en">20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6692" xml:lang="en">6692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6693" xml:lang="en">6693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005994" xml:lang="en">1005994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11179" xml:lang="en">solaris-at-directory-traversal(11179)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11180" xml:lang="en">solaris-at-race-condition(11180)</vuln:reference>
    </vuln:references>
    <vuln:summary>A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1074</vuln:cve-id>
    <vuln:published-datetime>2003-03-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52111-1" xml:lang="en">52111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7252" xml:lang="en">7252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006411" xml:lang="en">1006411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11657" xml:lang="en">solaris-newtask-root-access(11657)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1075</vuln:cve-id>
    <vuln:published-datetime>2003-01-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50240-1" xml:lang="en">50240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6709" xml:lang="en">6709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005996" xml:lang="en">1005996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11186" xml:lang="en">solaris-ftpd-dos(11186)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1076</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50904-1" xml:lang="en">50904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-050.shtml" xml:lang="en">N-050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7033" xml:lang="en">7033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006234" xml:lang="en">1006234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11496" xml:lang="en">solaris-sendmail-forward-privileges(11496)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1077</vuln:cve-id>
    <vuln:published-datetime>2003-03-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51300-1" xml:lang="en">51300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7032" xml:lang="en">7032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006233" xml:lang="en">1006233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11481" xml:lang="en">solaris-ufs-logging-dos(11481)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1078</vuln:cve-id>
    <vuln:published-datetime>2003-02-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1" xml:lang="en">51081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6989" xml:lang="en">6989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006195" xml:lang="en">1006195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11436" xml:lang="en">solaris-ftp-plaintext-password(11436)</vuln:reference>
    </vuln:references>
    <vuln:summary>The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1079</vuln:cve-id>
    <vuln:published-datetime>2003-02-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50626-1" xml:lang="en">50626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6883" xml:lang="en">6883</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006131" xml:lang="en">1006131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11368" xml:lang="en">solaris-udp-rpc-dos(11368)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1080</vuln:cve-id>
    <vuln:published-datetime>2003-02-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50751-1" xml:lang="en">50751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6838" xml:lang="en">6838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006084" xml:lang="en">1006084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11303" xml:lang="en">solaris-mail-unauthorized-access(11303)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1081</vuln:cve-id>
    <vuln:published-datetime>2003-09-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-46903-1" xml:lang="en">46903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3411&amp;cid=1" xml:lang="en">ESB-2003.0621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-001.shtml" xml:lang="en">O-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/464817" xml:lang="en">VU#464817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5698" xml:lang="en">5698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/10105" xml:lang="en">solaris-aspppls-tmpfile-symlink(10105)</vuln:reference>
    </vuln:references>
    <vuln:summary>Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:-"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:-</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1082</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:22.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50008-1" xml:lang="en">50008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-105.shtml" xml:lang="en">N-105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/596748" xml:lang="en">VU#596748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6639" xml:lang="en">6639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005935" xml:lang="en">1005935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11083" xml:lang="en">solaris-utmp-update-bo(11083)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tildeslash:monit:1.4</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:1.4.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.0</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.1.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.2</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.2.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.3</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4.2</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4.3</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:3.0</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:3.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:3.2</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:4.0</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1083</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-14.xml" xml:lang="en">GLSA-200403-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/623854" xml:lang="en">VU#623854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/345417" xml:lang="en">20031124 Monit 4.1 HTTP interface multiple security vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9099" xml:lang="en">9099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tildeslash.com/monit/dist/CHANGES.txt" xml:lang="en">http://www.tildeslash.com/monit/dist/CHANGES.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13817" xml:lang="en">monit-http-bo(13817)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tildeslash:monit:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tildeslash:monit:1.4</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:1.4.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.0</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.1.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.2</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.2.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.3</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4.2</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:2.4.3</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:3.0</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:3.1</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:3.2</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:4.0</vuln:product>
      <vuln:product>cpe:/a:tildeslash:monit:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1084</vuln:cve-id>
    <vuln:published-datetime>2003-11-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-14.xml" xml:lang="en">GLSA-200403-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/206382" xml:lang="en">VU#206382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/345417" xml:lang="en">20031124 Monit 4.1 HTTP interface multiple security vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9098" xml:lang="en">9098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tildeslash.com/monit/dist/CHANGES.txt" xml:lang="en">http://www.tildeslash.com/monit/dist/CHANGES.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13818" xml:lang="en">monit-negative-content-dos(13818)</vuln:reference>
    </vuln:references>
    <vuln:summary>Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:thomson:tcm_cable_modem:305"/>
        <cpe-lang:fact-ref name="cpe:/h:thomson:tcm_cable_modem:315"/>
        <cpe-lang:fact-ref name="cpe:/h:thomson:tcw_cable_modem:690"/>
        <cpe-lang:fact-ref name="cpe:/h:thomson:tcw_cable_modem:690_st42.03.0a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1085</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014062.html" xml:lang="en">20031123 Thomnson TCM315 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014068.html" xml:lang="en">20031124 Thomnson TCM315 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=110888093214678&amp;w=2" xml:lang="en">20050219 Re: [Full-Disclosure] Thomson TCW690 Denial Of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=110880725322192&amp;w=2" xml:lang="en">20050219 Thomson TCW690 Denial Of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/345414" xml:lang="en">20031123 Thomnson TCM315 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9091" xml:lang="en">9091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.shellsec.net/leer_advisory.php?id=2" xml:lang="en">http://www.shellsec.net/leer_advisory.php?id=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13815" xml:lang="en">thomson-http-get-dos(13815)</vuln:reference>
    </vuln:references>
    <vuln:summary>The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pmachine:pmachine_free"/>
        <cpe-lang:fact-ref name="cpe:/a:pmachine:pmachine_pro:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pmachine:pmachine_pro:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pmachine:pmachine_free</vuln:product>
      <vuln:product>cpe:/a:pmachine:pmachine_pro:2.2</vuln:product>
      <vuln:product>cpe:/a:pmachine:pmachine_pro:2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1086</vuln:cve-id>
    <vuln:published-datetime>2003-06-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:39:16.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105638414205498&amp;w=2" xml:lang="en">20030623 pMachine (PHP) : Include() Security Hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pmachine.com/forum/threads.php?id=7274_0_13_0_C" xml:lang="en">http://www.pmachine.com/forum/threads.php?id=7274_0_13_0_C</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1087</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=109292319608851&amp;w=2" xml:lang="en">SSRT3460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7827" xml:lang="en">7827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12199" xml:lang="en">hp-diagmond-dos(12199)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.0</vuln:product>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.1</vuln:product>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.2</vuln:product>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.3</vuln:product>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.4</vuln:product>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1088</vuln:cve-id>
    <vuln:published-datetime>2003-08-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106063199925536&amp;w=2" xml:lang="en">20030811 ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013365" xml:lang="en">1013365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8388" xml:lang="en">8388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12867" xml:lang="en">zorum-index-xss(12867)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpoutsourcing:zorum:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpoutsourcing:zorum:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1089</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106063199925536&amp;w=2" xml:lang="en">20030811 ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013365" xml:lang="en">1013365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8396" xml:lang="en">8396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12868" xml:lang="en">zorum-index-path-disclosure(12868)</vuln:reference>
    </vuln:references>
    <vuln:summary>index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.0</vuln:product>
      <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1090</vuln:cve-id>
    <vuln:published-datetime>2003-02-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:43.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104454984001076&amp;w=2" xml:lang="en">20030206 AbsoluteTelnet 2.00 buffer overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/666073" xml:lang="en">VU#666073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6785" xml:lang="en">6785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11265" xml:lang="en">absolutetelnet-title-bar-bo(11265)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_broadcaster:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1091</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0245.html" xml:lang="en">20030522 QuickTime/Darwin Streaming Server security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006822" xml:lang="en">1006822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/148564" xml:lang="en">VU#148564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7660" xml:lang="en">7660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12054" xml:lang="en">darwin-mp3broadcaster-code-execution(12054)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.30"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.33"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.34"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.35"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.36"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.37"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.39"/>
        <cpe-lang:fact-ref name="cpe:/a:christos_zoulas:file_1:3.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.28</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.30</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.32</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.33</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.34</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.35</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.36</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.37</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.39</vuln:product>
      <vuln:product>cpe:/a:christos_zoulas:file_1:3.40</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1092</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/100937" xml:lang="en">VU#100937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313847" xml:lang="en">OpenPKG-SA-2003.017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7009" xml:lang="en">7009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11488" xml:lang="en">file-afctr-memory-allocation(11488)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1093</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-24.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-24.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/331937" xml:lang="en">VU#331937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6586" xml:lang="en">6586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11057" xml:lang="en">weblogic-error-password-disclosure(11057)</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1094</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/999788" xml:lang="en">VU#999788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8320" xml:lang="en">8320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12799" xml:lang="en">weblogic-gain-privileges(12799)</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1095</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/691153" xml:lang="en">VU#691153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7130" xml:lang="en">7130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11555" xml:lang="en">weblogic-app-reauthentication-bypass(11555)</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:leap"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:leap</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1096</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=108135227731965&amp;w=2" xml:lang="en">20040407 Release of Cisco Attack tool Asleap</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sn-20030802-leap.shtml" xml:lang="en">20030803 Dictionary Attack on Cisco LEAP Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/473108" xml:lang="en">VU#473108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/340119" xml:lang="en">20031003 Dictionary attack against Cisco's LEAP, Wireless LANs vulnerable</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/340365" xml:lang="en">20031006 Weaknesses in LEAP Challenge/Response</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8755" xml:lang="en">8755</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12804" xml:lang="en">cisco-leap-dictionary(12804)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1097</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:18.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5611" name="oval:org.mitre.oval:def:5611"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-04/0374.html" xml:lang="en">20030429 HPUX rexec buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-088.shtml" xml:lang="en">N-088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/322540" xml:lang="en">VU#322540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/CRDY-5MJKM4" xml:lang="en">HPSBUX0304-257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7459" xml:lang="en">7459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11890" xml:lang="en">hp-rexec-command-bo(11890)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1098</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:18.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5765" name="oval:org.mitre.oval:def:5765"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/862401" xml:lang="en">VU#862401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/IAFY-5HVQDJ" xml:lang="en">HPSBUX0301-238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6638" xml:lang="en">6638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005936" xml:lang="en">1005936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11094" xml:lang="en">hp-xserver-gain-privileges(11094)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1099</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:18.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5788" name="oval:org.mitre.oval:def:5788"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-032.shtml" xml:lang="en">O-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/509454" xml:lang="en">VU#509454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/CRDY-5VFQA3" xml:lang="en">HPSBUX0312-304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9141" xml:lang="en">9141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13882" xml:lang="en">hp-shar-tmpfile-symlink(13882)</vuln:reference>
    </vuln:references>
    <vuln:summary>shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:3.5.1</vuln:product>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:3.9</vuln:product>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1100</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/488684" xml:lang="en">VU#488684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/security_info/vuln_pr0305.html" xml:lang="en">http://www.procheckup.com/security_info/vuln_pr0305.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8815" xml:lang="en">8815</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13399" xml:lang="en">hummingbird-docsfusionserver-multiple-xss(13399)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:3.5.1</vuln:product>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:3.9</vuln:product>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1101</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/715548" xml:lang="en">VU#715548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/security_info/vuln_pr0303.html" xml:lang="en">http://www.procheckup.com/security_info/vuln_pr0303.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8816" xml:lang="en">8816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13398" xml:lang="en">Hummingbird-docsfusionserver-disclose-path(13398)</vuln:reference>
    </vuln:references>
    <vuln:summary>Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1102</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/989580" xml:lang="en">VU#989580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/security_info/vuln_pr0302.html" xml:lang="en">http://www.procheckup.com/security_info/vuln_pr0302.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13397" xml:lang="en">Hummingbird-docsfusionserver-file-access(13397)</vuln:reference>
    </vuln:references>
    <vuln:summary>Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:cyberdocs:3.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:3.1</vuln:product>
      <vuln:product>cpe:/a:hummingbird:cyberdocs:3.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1103</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/368300" xml:lang="en">VU#368300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/security_info/vuln_pr0304.html" xml:lang="en">http://www.procheckup.com/security_info/vuln_pr0304.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8800" xml:lang="en">8800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13401" xml:lang="en">hummingbird-docsfusionserver-sql-injection(13401)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:tivoli_firewall_toolbox:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:tivoli_firewall_toolbox:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1104</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0307.html" xml:lang="en">20030320 IBM Tivoli Firewall Security Toolbox buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/210937" xml:lang="en">VU#210937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7154" xml:lang="en">7154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11584" xml:lang="en">tivoli-tfst-relay-bo(11584)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1105</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:51.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/813208" xml:lang="en">VU#813208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032" xml:lang="en">MS03-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13029" xml:lang="en">ie-input-type-dos(13029)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1106</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-24T09:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?kbid=330716" xml:lang="en">330716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/155252" xml:lang="en">VU#155252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8195" xml:lang="en">8195</vuln:reference>
    </vuln:references>
    <vuln:summary>The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_player:6.4</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:7.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1107</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:44.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;en-us;828026" xml:lang="en">828026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/222044" xml:lang="en">VU#222044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13375" xml:lang="en">mediaplayer-dhtml-code-execution(13375)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alcatel-lucent:omnipcx:5.0::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alcatel-lucent:omnipcx:5.0::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1108</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:18.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5831" name="oval:org.mitre.oval:def:5831"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xa"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xd"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xd1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xd3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xd4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xe"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xe2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xe3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xh"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xq"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xs"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%281%29xs1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29t4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xa"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xa1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xa5"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xb"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xb3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xb4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xf"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xg"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xh"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xh2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xh3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xi"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xi1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xi2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xj"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xj1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xk"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xk2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xn"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xt"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xt3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xu"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%282%29xu2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2811%29t"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xa"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xb"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xc"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xd"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xe"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xf"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xg"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xh"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xi"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xj"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xk"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xl"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xm"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xn"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xq"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xr"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xs"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xt"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xw"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:ip_phone_7940"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:ip_phone_7960"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%283.210%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%285%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%286%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.2%287%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%281.200%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:5.3%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.0%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.1%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.2%281%29"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ip_phone_7940</vuln:product>
      <vuln:product>cpe:/h:cisco:ip_phone_7960</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xd1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xd3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xd4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xe2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xe3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%281%29xs1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29t4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xa1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xa5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xb3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xb4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xh2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xh3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xi1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xi2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xj1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xk2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xt3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%282%29xu2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2811%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xw</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%283.210%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%285%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%286%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.2%287%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%281.200%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:5.3%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.0%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.1%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.2%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1109</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:18.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml" xml:lang="en">20030221 Multiple Product Vulnerabilities Found by PROTOS SIP Test Suite</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006143" xml:lang="en">1006143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006144" xml:lang="en">1006144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006145" xml:lang="en">1006145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:columbia_university:sipc:1.74"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:columbia_university:sipc:1.74</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1110</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006167" xml:lang="en">1006167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cs.columbia.edu/~xiaotaow/sipc/ouspg.html" xml:lang="en">http://www.cs.columbia.edu/~xiaotaow/sipc/ouspg.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dynamicsoft:appengine"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dynamicsoft:appengine</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1111</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.dynamicsoft.com/support/advisory/ca-2003-06.php" xml:lang="en">http://www.dynamicsoft.com/support/advisory/ca-2003-06.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in multiple dynamicsoft products including y and certain demo products for AppEngine allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:ingate:ingate_firewall"/>
        <cpe-lang:fact-ref name="cpe:/h:ingate:ingate_siparator"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:ingate:ingate_firewall</vuln:product>
      <vuln:product>cpe:/h:ingate:ingate_siparator</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1112</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:iptel:sip_express_router:0.8.8"/>
        <cpe-lang:fact-ref name="cpe:/h:iptel:sip_express_router:0.8.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:iptel:sip_express_router:0.8.8</vuln:product>
      <vuln:product>cpe:/h:iptel:sip_express_router:0.8.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1113</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.iptel.org/ser/security/" xml:lang="en">http://www.iptel.org/ser/security/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:mediatrix_telecom:voip_access_devices_and_gateways:sipv2.3"/>
        <cpe-lang:fact-ref name="cpe:/h:mediatrix_telecom:voip_access_devices_and_gateways:sipv2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:mediatrix_telecom:voip_access_devices_and_gateways:sipv2.3</vuln:product>
      <vuln:product>cpe:/h:mediatrix_telecom:voip_access_devices_and_gateways:sipv2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1114</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:nortel:succession_communication_server_2000"/>
        <cpe-lang:fact-ref name="cpe:/h:nortel:succession_communication_server_2000:::compact"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:nortel:succession_communication_server_2000</vuln:product>
      <vuln:product>cpe:/h:nortel:succession_communication_server_2000:::compact</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1115</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-06.html" xml:lang="en">CA-2003-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" xml:lang="en">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/528719" xml:lang="en">VU#528719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6904" xml:lang="en">6904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379" xml:lang="en">sip-invite(11379)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:e-business_suite:10.7</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.0</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.1</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.2</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.3</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.4</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.6</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.7</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1116</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105012832418415&amp;w=2" xml:lang="en">20030411 Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006550" xml:lang="en">1006550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm" xml:lang="en">http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/168873" xml:lang="en">VU#168873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7325" xml:lang="en">7325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11768" xml:lang="en">oracle-rra-authentication-bypass(11768)</vuln:reference>
    </vuln:references>
    <vuln:summary>The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realsystem_proxy:8"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realsystem_server:6"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realsystem_server:7"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realsystem_server:8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realsystem_proxy:8</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realsystem_server:6</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realsystem_server:7</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realsystem_server:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1117</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1003604" xml:lang="en">1003604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/bufferoverflow.html" xml:lang="en">http://service.real.com/help/faq/security/bufferoverflow.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/143627" xml:lang="en">VU#143627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/912219" xml:lang="en">VU#912219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11362" xml:lang="en">realsystem-malformed-url-bo(11362)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:university_of_california:seti_at_home:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_california:seti_at_home:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_california:seti_at_home:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_california:seti_at_home:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_california:seti_at_home:3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_california:seti_at_home:3.3</vuln:product>
      <vuln:product>cpe:/a:university_of_california:seti_at_home:3.4</vuln:product>
      <vuln:product>cpe:/a:university_of_california:seti_at_home:3.5</vuln:product>
      <vuln:product>cpe:/a:university_of_california:seti_at_home:3.6</vuln:product>
      <vuln:product>cpe:/a:university_of_california:seti_at_home:3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1118</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004383.html" xml:lang="en">20030406 Seti@home information leakage and remote compromise</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/146785" xml:lang="en">VU#146785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7292" xml:lang="en">7292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11731" xml:lang="en">seti@home-newline-bo(11731)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ssh:secure_shell:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:secure_shell:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssh:secure_shell:3.1</vuln:product>
      <vuln:product>cpe:/a:ssh:secure_shell:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1119</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:05.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T14:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/333980" xml:lang="en">VU#333980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ssh.com/company/newsroom/article/476/" xml:lang="en">http://www.ssh.com/company/newsroom/article/476/</vuln:reference>
    </vuln:references>
    <vuln:summary>SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ssh:tectia_server:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:tectia_server:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssh:tectia_server:4.0.3</vuln:product>
      <vuln:product>cpe:/a:ssh:tectia_server:4.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1120</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2004/Mar/1009532.html" xml:lang="en">1009532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/814198" xml:lang="en">VU#814198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9956" xml:lang="en">9956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ssh.com/company/newsroom/article/520/" xml:lang="en">http://www.ssh.com/company/newsroom/article/520/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15585" xml:lang="en">sshtectiaserver-passwdplugin-race-condition(15585)</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptlogic:scriptlogic:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1121</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/231705" xml:lang="en">VU#231705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/609137" xml:lang="en">VU#609137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/CRDY-5EXQRP" xml:lang="en">http://www.kb.cert.org/vuls/id/CRDY-5EXQRP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/CRDY-5EXQSV" xml:lang="en">http://www.kb.cert.org/vuls/id/CRDY-5EXQSV</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7475" xml:lang="en">7475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7477" xml:lang="en">7477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11920" xml:lang="en">scriptlogic-rpc-modify-registry(11920)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11921" xml:lang="en">scriptlogic-runadmin-admin-access(11921)</vuln:reference>
    </vuln:references>
    <vuln:summary>Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptlogic:scriptlogic:4.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptlogic:scriptlogic:4.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1122</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/813737" xml:lang="en">VU#813737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/CRDY-5EXQT9" xml:lang="en">http://www.kb.cert.org/vuls/id/CRDY-5EXQT9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7476" xml:lang="en">7476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11922" xml:lang="en">scriptlogic-logs$-insecure-permissions(11922)</vuln:reference>
    </vuln:references>
    <vuln:summary>ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_10::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_10::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_10::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_11::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_11::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_11::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.2.2_12::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01a::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_04::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.0_01::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2:update10:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2:update10:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2:update10:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2_003::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2_011::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2_011::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2_011::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.2.2_012::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update4:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update4:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update4:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.0_01::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.0_01::windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jdk:1.2.2::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_10::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_10::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_10::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_11::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_11::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_11::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.2.2_12::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01a::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_04::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.4::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.4::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.4::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.4.0_01::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2:update10:linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2:update10:solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2:update10:windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2_003::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2_011::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2_011::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2_011::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.2.2_012::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2:linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2:solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2:windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update4:windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5:linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5:solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5:windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1:linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1:solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1:windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update4:solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update4:windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4::windows</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.0_01::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.0_01::windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1123</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006935" xml:lang="en">1006935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55100-1" xml:lang="en">55100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/393292" xml:lang="en">VU#393292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7824" xml:lang="en">7824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12189" xml:lang="en">sun-applet-access-information(12189)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:management%2bcenter:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:management%2bcenter:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:management%2bcenter:3.0_revenue_release"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:management%2bcenter:2.1.1</vuln:product>
      <vuln:product>cpe:/a:sun:management%2bcenter:3.0</vuln:product>
      <vuln:product>cpe:/a:sun:management%2bcenter:3.0_revenue_release</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1124</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55141-1" xml:lang="en">55141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/758932" xml:lang="en">VU#758932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7960" xml:lang="en">7960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12343" xml:lang="en">sunmc-files-writable-permissions(12343)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:4.16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_directory_server:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:one_directory_server:4.16</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.0</vuln:product>
      <vuln:product>cpe:/a:sun:one_directory_server:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1125</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:06.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T13:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52102-1" xml:lang="en">52102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/195644" xml:lang="en">VU#195644</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:one_web_server:6.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_web_server:6.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:one_web_server:6.0:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:one_web_server:6.0:sp3</vuln:product>
      <vuln:product>cpe:/a:sun:one_web_server:6.0:sp4</vuln:product>
      <vuln:product>cpe:/a:sun:one_web_server:6.0:sp5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1126</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:06.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T13:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56180-1" xml:lang="en">56180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/636964" xml:lang="en">VU#636964</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:whale_communications:e-gap:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:whale_communications:e-gap:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1127</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/371470" xml:lang="en">VU#371470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/security_info/vuln_pr0307.html" xml:lang="en">http://www.procheckup.com/security_info/vuln_pr0307.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9431" xml:lang="en">9431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14869" xml:lang="en">egap-url-information-disclosure(14869)</vuln:reference>
    </vuln:references>
    <vuln:summary>Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x2_studios:xmms_remote:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x2_studios:xmms_remote:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1128</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/583020" xml:lang="en">VU#583020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7534" xml:lang="en">7534</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.x2studios.com/index.php?page=kb&amp;id=16" xml:lang="en">http://www.x2studios.com/index.php?page=kb&amp;id=16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12139" xml:lang="en">xmms-remote-command-execution(12139)</vuln:reference>
    </vuln:references>
    <vuln:summary>XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yahoo:audio_conferencing_activex_control:1.0.0.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yahoo:audio_conferencing_activex_control:1.0.0.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1129</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:45.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://help.yahoo.com/help/us/mesg/use/use-45.html" xml:lang="en">http://help.yahoo.com/help/us/mesg/use/use-45.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/272644" xml:lang="en">VU#272644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/323439" xml:lang="en">20030530 Yahoo! Security Advisory: Yahoo! Voice Chat</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7561" xml:lang="en">7561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12130" xml:lang="en">yahoo-audio-bo(12130)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1130">
    <vuln:cve-id>CVE-2003-1130</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:53.977-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-1071.  Reason: This candidate is a duplicate of CVE-2003-1071.  Notes: All CVE users should reference CVE-2003-1071 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:activecampaign:knowledgebuilder:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:activecampaign:knowledgebuilder:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:activecampaign:knowledgebuilder:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:activecampaign:knowledgebuilder:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:activecampaign:knowledgebuilder:2.0.1</vuln:product>
      <vuln:product>cpe:/a:activecampaign:knowledgebuilder:2.1.0</vuln:product>
      <vuln:product>cpe:/a:activecampaign:knowledgebuilder:2.1.4</vuln:product>
      <vuln:product>cpe:/a:activecampaign:knowledgebuilder:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1131</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=111066494323543&amp;w=2" xml:lang="en">20050312 KnowledgeBase</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348359" xml:lang="en">20031224 Remote Code Execution in Knowledge Builder.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9292" xml:lang="en">9292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14078" xml:lang="en">knowledgebuilder-indexphp-file-include(14078)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:content_services_switch_11000"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:content_services_switch_11500"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:content_services_switch_11000</vuln:product>
      <vuln:product>cpe:/h:cisco:content_services_switch_11500</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1132</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:07.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T12:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030430-dns.shtml" xml:lang="en">20041008 Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/714121" xml:lang="en">VU#714121</vuln:reference>
    </vuln:references>
    <vuln:summary>The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.011"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.015"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.028"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.029"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.031"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.032"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.33"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.34"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.035"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.036"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.037"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.039"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.041"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.42"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.42f"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.043"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.44"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.45"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.46"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.48"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.49"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.51"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.52"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.53d"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:1.101"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ritlabs:the_bat:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.1</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.5</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.011</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.14</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.015</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.17</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.18</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.19</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.21</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.22</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.028</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.029</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.031</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.032</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.33</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.34</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.035</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.036</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.037</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.039</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.041</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.42</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.42f</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.043</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.44</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.45</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.46</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.47</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.48</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.49</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.51</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.52</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.53d</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:1.101</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:2.0</vuln:product>
      <vuln:product>cpe:/a:ritlabs:the_bat:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1133</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008004" xml:lang="en">1008004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342485" xml:lang="en">20031025 Some serious security holes in 'The Bat!'</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8891" xml:lang="en">8891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13527" xml:lang="en">thebat-access-email(13527)</vuln:reference>
    </vuln:references>
    <vuln:summary>Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:java:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java:1.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:java:1.4.1</vuln:product>
      <vuln:product>cpe:/a:sun:java:1.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1134</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:08.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T12:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012773.html" xml:lang="en">20031026 Java 1.4.2_02 InsecurityManager JVM crash</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8892" xml:lang="en">8892</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yahoo:messenger:5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1135</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:08.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T12:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342472" xml:lang="en">20031026 Buffer Overflow in Yahoo messenger Client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8894" xml:lang="en">8894</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:chi_kien_uong:chi_kien_uong_guestbook:1.51"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:chi_kien_uong:chi_kien_uong_guestbook:1.51</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1136</vuln:cve-id>
    <vuln:published-datetime>2003-10-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008006" xml:lang="en">1008006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342475" xml:lang="en">20031026 New Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8895" xml:lang="en">8895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8896" xml:lang="en">8896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13522" xml:lang="en">guestbook-html-xss(13522)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13523" xml:lang="en">guestbook-doublequotation-xss(13523)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:charles_steinkuehler:sh-httpd:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:charles_steinkuehler:sh-httpd:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:charles_steinkuehler:sh-httpd:0.3</vuln:product>
      <vuln:product>cpe:/a:charles_steinkuehler:sh-httpd:0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1137</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342473" xml:lang="en">20031027 sh-httpd `wildcard character' vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342766" xml:lang="en">20031028 Re: sh-httpd `wildcard character' vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8897" xml:lang="en">8897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13519" xml:lang="en">shtttpd-get-information-disclosure(13519)</vuln:reference>
    </vuln:references>
    <vuln:summary>Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:redhat:interchange:2.0.40_21.5::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:interchange:2.0.40_21.5::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1138</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:08.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T11:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342578" xml:lang="en">20031027 Root Directory Listing on RH default apache</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8898" xml:lang="en">8898</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:musicqueue:musicqueue:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1139</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008014" xml:lang="en">1008014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342476" xml:lang="en">20031027 Musicqueue multiple local vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8899" xml:lang="en">8899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13520" xml:lang="en">musicqueue-tmpfile-symlink(13520)</vuln:reference>
    </vuln:references>
    <vuln:summary>Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:musicqueue:musicqueue:1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:musicqueue:musicqueue:0.9</vuln:product>
      <vuln:product>cpe:/a:musicqueue:musicqueue:0.9.1</vuln:product>
      <vuln:product>cpe:/a:musicqueue:musicqueue:0.9.2</vuln:product>
      <vuln:product>cpe:/a:musicqueue:musicqueue:1.0</vuln:product>
      <vuln:product>cpe:/a:musicqueue:musicqueue:1.1</vuln:product>
      <vuln:product>cpe:/a:musicqueue:musicqueue:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1140</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0021.html" xml:lang="en">20031027 Musicqueue multiple local vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008014" xml:lang="en">1008014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342476" xml:lang="en">20031027 Musicqueue multiple local vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8903" xml:lang="en">8903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13521" xml:lang="en">musicqueue-getconf-bo(13521)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:network_instruments:niprint_lpd-lpr_print_server:4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:network_instruments:niprint_lpd-lpr_print_server:4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1141</vuln:cve-id>
    <vuln:published-datetime>2003-11-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343257" xml:lang="en">20031104 SRT2003-11-02-0115 - NIPrint LPD-LPR Remote overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343318" xml:lang="en">20031104 NIPrint remote exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8968" xml:lang="en">8968</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13591" xml:lang="en">niprint-bo(13591)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:network_instruments:niprint_lpd-lpr_print_server:4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1142</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343258" xml:lang="en">20031104 SRT2003-11-02-0218 - NIPrint LPD-LPR Local Help API SYSTEM exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8969" xml:lang="en">8969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13592" xml:lang="en">niprint-helpapi-gain-privileges(13592)</vuln:reference>
    </vuln:references>
    <vuln:summary>Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:croteam:serioussam:test_2_2.1_a"/>
        <cpe-lang:fact-ref name="cpe:/a:croteam:serioussam:the_first_encounter_1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:croteam:serioussam:the_second_encounter_1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:croteam:serioussam:the_second_encounter_demo"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:croteam:serioussam:test_2_2.1_a</vuln:product>
      <vuln:product>cpe:/a:croteam:serioussam:the_first_encounter_1.0.5</vuln:product>
      <vuln:product>cpe:/a:croteam:serioussam:the_second_encounter_1.0.5</vuln:product>
      <vuln:product>cpe:/a:croteam:serioussam:the_second_encounter_demo</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1143</vuln:cve-id>
    <vuln:published-datetime>2003-10-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342957" xml:lang="en">20031030 Serious Sam is not so serious</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8936" xml:lang="en">8936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13618" xml:lang="en">serioussam-games-packet-dos(13618)</vuln:reference>
    </vuln:references>
    <vuln:summary>Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:perception:liteserve:1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:perception:liteserve:1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:perception:liteserve:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:perception:liteserve:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:perception:liteserve:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:perception:liteserve:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:perception:liteserve:1.25</vuln:product>
      <vuln:product>cpe:/a:perception:liteserve:1.28</vuln:product>
      <vuln:product>cpe:/a:perception:liteserve:2.0</vuln:product>
      <vuln:product>cpe:/a:perception:liteserve:2.0.1</vuln:product>
      <vuln:product>cpe:/a:perception:liteserve:2.0.2</vuln:product>
      <vuln:product>cpe:/a:perception:liteserve:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1144</vuln:cve-id>
    <vuln:published-datetime>2003-11-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008093" xml:lang="en">1008093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343322" xml:lang="en">20031104 Liteserve Buffer Overflow in Handling Server's Log.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8971" xml:lang="en">8971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13599" xml:lang="en">liteserve-log-entry-bo(13599)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openautoclassifieds:openautoclassifieds:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1145</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343806" xml:lang="en">20031107 OpenAutoClassifieds XSS attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8972" xml:lang="en">8972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13604" xml:lang="en">openautoclassifieds-friendmail-xss(13604)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:john_beatty:easy_php_photo_album:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:john_beatty:easy_php_photo_album:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1146</vuln:cve-id>
    <vuln:published-datetime>2003-05-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:09.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T10:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.nnov.ru/docs5347.html" xml:lang="en">http://security.nnov.ru/docs5347.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8977" xml:lang="en">8977</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1147">
    <vuln:cve-id>CVE-2003-1147</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:21:55.337-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0955.  Reason: This candidate is a duplicate of CVE-2003-0955.  Notes: All CVE users should reference CVE-2003-0955 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:les_visiteurs:les_visiteurs:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:les_visiteurs:les_visiteurs:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1148</vuln:cve-id>
    <vuln:published-datetime>2003-10-25T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0262.html" xml:lang="en">20031026 Les Visiteurs v2.0.1 code injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008011" xml:lang="en">1008011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017065" xml:lang="en">1017065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8902" xml:lang="en">8902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13529" xml:lang="en">les-visiteurs-file-include(13529)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2003_6.0.4.34"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2003_6.0.4.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1149</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342548" xml:lang="en">20031027 Norton Internet Security 2003 XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8904" xml:lang="en">8904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13528" xml:lang="en">norton-is-blocked-xss(13528)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:zenworks_desktops:3.2:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:zenworks_desktops:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:zenworks_desktops:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:6.0:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:zenworks_desktops:3.2:sp2</vuln:product>
      <vuln:product>cpe:/a:novell:zenworks_desktops:4.0</vuln:product>
      <vuln:product>cpe:/a:novell:zenworks_desktops:4.0.1</vuln:product>
      <vuln:product>cpe:/o:novell:netware:6.0:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1150</vuln:cve-id>
    <vuln:published-datetime>2003-10-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8907" xml:lang="en">8907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13564" xml:lang="en">novell-portmapper-bo(13564)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fastream:netfile_ftp_web_server:6.0.3.588"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1151</vuln:cve-id>
    <vuln:published-datetime>2003-10-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008020" xml:lang="en">1008020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342678" xml:lang="en">20031028 Fastream NetFile FTP/WebServer 6.0 CSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8908" xml:lang="en">8908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13535" xml:lang="en">fastream-nonexistent-url-xss(13535)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:infrontech:webtide:7.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:infrontech:webtide:7.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1152</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:46.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012811.html" xml:lang="en">20031028 STG Security Advisory: [SSA-20031025-05] InfronTech WebTide 7.04 Directory and File Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008016" xml:lang="en">1008016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8909" xml:lang="en">8909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13533" xml:lang="en">webtide-file-disclosure(13533)</vuln:reference>
    </vuln:references>
    <vuln:summary>WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").</vuln:summary>
  </entry>
  <entry id="CVE-2003-1153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bytehoard:bytehoard:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bytehoard:bytehoard:0.71"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bytehoard:bytehoard:0.7</vuln:product>
      <vuln:product>cpe:/a:bytehoard:bytehoard:0.71</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1153</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012801.html" xml:lang="en">20031027 Bytehoard File Disclosure VUlnerability Sequel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8910" xml:lang="en">8910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13531" xml:lang="en">bytehoard-view-file(13531)</vuln:reference>
    </vuln:references>
    <vuln:summary>byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.6_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.1</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.4</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.5</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.6</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.6_sp1</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1154</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&amp;More=" xml:lang="en">http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&amp;More=</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8982" xml:lang="en">8982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13611" xml:lang="en">mailsweeper-zip-virus-bypass(13611)</vuln:reference>
    </vuln:references>
    <vuln:summary>MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha10"/>
        <cpe-lang:fact-ref name="cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha11"/>
        <cpe-lang:fact-ref name="cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha12"/>
        <cpe-lang:fact-ref name="cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha13"/>
        <cpe-lang:fact-ref name="cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha10</vuln:product>
      <vuln:product>cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha11</vuln:product>
      <vuln:product>cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha12</vuln:product>
      <vuln:product>cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha13</vuln:product>
      <vuln:product>cpe:/a:x-cd-roast:x-cd-roast:0.98_alpha14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1155</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008094" xml:lang="en">1008094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8983" xml:lang="en">8983</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.xcdroast.org/xcdr098/changelog-a15.html" xml:lang="en">http://www.xcdroast.org/xcdr098/changelog-a15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13612" xml:lang="en">xcdroast-symlink(13612)</vuln:reference>
    </vuln:references>
    <vuln:summary>X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.2::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.2_02::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2:linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jdk:1.4.2::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.4.2_02::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2::linux</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2:linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1156</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343038" xml:lang="en">20031031 Advisory: Sun's jre/jdk 1.4.2 multiple vulernabilities in linuxinstallers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8937" xml:lang="en">8937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13570" xml:lang="en">sun-jre-java-symlink(13570)</vuln:reference>
    </vuln:references>
    <vuln:summary>Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:citrix:metaframe:1.0::xp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:citrix:metaframe:1.0::xp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1157</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343040" xml:lang="en">20031031 IRM 008: Citrix Metaframe XP is vulnerable to Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27948" xml:lang="en">27948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8939" xml:lang="en">8939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13569" xml:lang="en">metaframe-error-message-xss(13569)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/40782" xml:lang="en">citrix-webmanager-login-xss(40782)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plug_and_play_software:plug_and_play_web_server:1.0.002c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plug_and_play_software:plug_and_play_web_server:1.0.002c</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1158</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-09/0275.html" xml:lang="en">20030917 Denial Of Service in Plug &amp; Play Web (FTP) Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8667" xml:lang="en">8667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13219" xml:lang="en">plugandplaywebserver-multiple-commands-dos(13219)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plug_and_play:plug_and_play_web_server_proxy:1.0002c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plug_and_play:plug_and_play_web_server_proxy:1.0002c</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1159</vuln:cve-id>
    <vuln:published-datetime>2003-10-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0343.html" xml:lang="en">20031031 DoS in Plug and Play Web Server Proxy Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8941" xml:lang="en">8941</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13572" xml:lang="en">plugandplaywebserver-get-dos(13572)</vuln:reference>
    </vuln:references>
    <vuln:summary>Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:seyeon:flexwatch_network_video_server:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:seyeon:flexwatch_network_video_server:model_132"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:seyeon:flexwatch_network_video_server:2.2</vuln:product>
      <vuln:product>cpe:/a:seyeon:flexwatch_network_video_server:model_132</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1160</vuln:cve-id>
    <vuln:published-datetime>2003-10-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt" xml:lang="en">http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008049" xml:lang="en">1008049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8942" xml:lang="en">8942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13567" xml:lang="en">flexwatch-slash-admin-access(13567)</vuln:reference>
    </vuln:references>
    <vuln:summary>FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1161</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:12.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-23T09:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8987" xml:lang="en">8987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0621.html" xml:lang="en">[linux-kernel] 20031105 BK2CVS problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0627.html" xml:lang="en">[linux-kernel] 20031105 Re: BK2CVS problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0630.html" xml:lang="en">[linux-kernel] 20031105 Re: BK2CVS problem</vuln:reference>
    </vuln:references>
    <vuln:summary>exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:0.993_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:0.994_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:0.999_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.1_final"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:0.993_beta</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:0.994_beta</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:0.999_beta</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.0_beta</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.1_final</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2.1</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2.2</vuln:product>
      <vuln:product>cpe:/a:tritanium_scripts:tritanium_bulletin_board:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1162</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0348.html" xml:lang="en">20031031 Virginity Security Advisory 2003-002 : Tritanium Bulletin Board - Read and write from/to internal (protected) Threads</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8944" xml:lang="en">8944</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13587" xml:lang="en">tritanium-threadid-view-messages(13587)</vuln:reference>
    </vuln:references>
    <vuln:summary>index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ganglia:gmond:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:gmond:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:gmond:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:gmond:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:gmond:2.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ganglia:gmond:2.5.0</vuln:product>
      <vuln:product>cpe:/a:ganglia:gmond:2.5.1</vuln:product>
      <vuln:product>cpe:/a:ganglia:gmond:2.5.2</vuln:product>
      <vuln:product>cpe:/a:ganglia:gmond:2.5.3</vuln:product>
      <vuln:product>cpe:/a:ganglia:gmond:2.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1163</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ganglia.sourceforge.net/" xml:lang="en">http://ganglia.sourceforge.net/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343689" xml:lang="en">20031106 DoS for Ganglia</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8988" xml:lang="en">8988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13631" xml:lang="en">ganglia-gmond-dos(13631)</vuln:reference>
    </vuln:references>
    <vuln:summary>hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mldonkey:mldonkey:2.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mldonkey:mldonkey:2.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1164</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/013070.html" xml:lang="en">20031031 XSS In mldonkey - But....</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8946" xml:lang="en">8946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13615" xml:lang="en">mldonkey-xss(13615)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.49_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.50_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.51_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.52_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.60_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.61_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.62_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:0.63_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brs:webweaver:0.49_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.50_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.51_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.52_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.60_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.61_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.62_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:0.63_beta</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:1.0.1</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:1.0.2</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:1.0.3</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:1.0.4</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:1.0.5</vuln:product>
      <vuln:product>cpe:/a:brs:webweaver:1.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1165</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343111" xml:lang="en">20031101 BRS WebWeaver 1.06 remote DoS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8947" xml:lang="en">8947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13571" xml:lang="en">brswebweaver-useragent-bo(13571)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:http_commander:http_commander:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:http_commander:http_commander:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1166</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.http-com.com/Default.asp?section=Features" xml:lang="en">http://www.http-com.com/Default.asp?section=Features</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8948" xml:lang="en">8948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13622" xml:lang="en">http-commander-directory-traversal(13622)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gernot_stocker:kpopup:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gernot_stocker:kpopup:0.9.5_pre2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gernot_stocker:kpopup:0.9.1</vuln:product>
      <vuln:product>cpe:/a:gernot_stocker:kpopup:0.9.5_pre2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1167</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342736" xml:lang="en">20031028 Local root vuln in kpopup</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8915" xml:lang="en">8915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13540" xml:lang="en">kpopup-systemcall-execute-code(13540)</vuln:reference>
    </vuln:references>
    <vuln:summary>misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:http_commander:http_commander:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1168</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:13.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-22T23:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8949" xml:lang="en">8949</vuln:reference>
    </vuln:references>
    <vuln:summary>HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:datev:nutzungskontrolle:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:datev:nutzungskontrolle:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:datev:nutzungskontrolle:2.1</vuln:product>
      <vuln:product>cpe:/a:datev:nutzungskontrolle:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1169</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013113.html" xml:lang="en">20031101 DATEV Nutzungskontrolle Bypassing (REG)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8950" xml:lang="en">8950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13589" xml:lang="en">nutzungskontrolle-registry-security-bypass(13589)</vuln:reference>
    </vuln:references>
    <vuln:summary>DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gernot_stocker:kpopup:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gernot_stocker:kpopup:0.9.5_pre2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gernot_stocker:kpopup:0.9.1</vuln:product>
      <vuln:product>cpe:/a:gernot_stocker:kpopup:0.9.5_pre2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1170</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:13.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-22T23:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342736" xml:lang="en">20031028 Local root vuln in kpopup</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8918" xml:lang="en">8918</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mod_security:mod_security:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_security:mod_security:1.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_security:mod_security:1.7</vuln:product>
      <vuln:product>cpe:/a:mod_security:mod_security:1.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1171</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://adsystems.com.pl/adg-mod_security171.txt" xml:lang="en">http://adsystems.com.pl/adg-mod_security171.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008025" xml:lang="en">1008025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.modsecurity.org/download/CHANGES" xml:lang="en">http://www.modsecurity.org/download/CHANGES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342767" xml:lang="en">20031028 mod_security 1.7RC1 to 1.7.1 vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8919" xml:lang="en">8919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13543" xml:lang="en">mod-security-secfilterout-bo(13543)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:cocoon:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cocoon:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cocoon:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:cocoon:2.1</vuln:product>
      <vuln:product>cpe:/a:apache:cocoon:2.1.2</vuln:product>
      <vuln:product>cpe:/a:apache:cocoon:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1172</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:47.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.apache.org/bugzilla/show_bug.cgi?id=23949" xml:lang="en">http://issues.apache.org/bugzilla/show_bug.cgi?id=23949</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007993" xml:lang="en">1007993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/6W00L0U8KC.html" xml:lang="en">http://www.securiteam.com/securitynews/6W00L0U8KC.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8883" xml:lang="en">8883</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13499" xml:lang="en">apachecocoon-directory-traversal-bootini(13499)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:centrinity:centrinity_firstclass:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1173</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342765" xml:lang="en">20031028 FirstClass 7.1 HTTP Server: Remote Directory Listing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342909" xml:lang="en">20031030 Re: FirstClass 7.1 HTTP Server: Remote Directory Listing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8920" xml:lang="en">8920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13546" xml:lang="en">firstclass-view-unauthorized-files(13546)</vuln:reference>
    </vuln:references>
    <vuln:summary>Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:shoutcast_server:1.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nullsoft:shoutcast_server:1.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1174</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008080" xml:lang="en">1008080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343177" xml:lang="en">20031102 ShoutCast server 1.9.2/win32</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8954" xml:lang="en">8954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13586" xml:lang="en">shoutcast-long-icy-dos(13586)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:synthetic_reality:sympoll:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:synthetic_reality:sympoll:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1175</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834374&amp;group_id=64442&amp;atid=507493" xml:lang="en">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834374&amp;group_id=64442&amp;atid=507493</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8956" xml:lang="en">8956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13630" xml:lang="en">sympoll-indexphp-xss(13630)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bdc_enterprises:web_wiz_forums:6.34"/>
        <cpe-lang:fact-ref name="cpe:/a:bdc_enterprises:web_wiz_forums:7.01"/>
        <cpe-lang:fact-ref name="cpe:/a:bdc_enterprises:web_wiz_forums:7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bdc_enterprises:web_wiz_forums:6.34</vuln:product>
      <vuln:product>cpe:/a:bdc_enterprises:web_wiz_forums:7.01</vuln:product>
      <vuln:product>cpe:/a:bdc_enterprises:web_wiz_forums:7.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1176</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008100" xml:lang="en">1008100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343175" xml:lang="en">20031102 Unauthorized access in Web Wiz Forum</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343314" xml:lang="en">20031104 Re: Unauthorized access in Web Wiz Forum</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8957" xml:lang="en">8957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13581" xml:lang="en">webwizforums-quotemode-message-access(13581)</vuln:reference>
    </vuln:references>
    <vuln:summary>post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:3.3_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:3.3_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:4.1_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:4.2_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:4.2_sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:3.3</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:3.3_sp1</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:3.3_sp2</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:4.1</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:4.1_sp1</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:4.2</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:4.2_sp1</vuln:product>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:4.2_sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1177</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2003-q4/1459.html" xml:lang="en">20031024 Vulnerability in MERCUR Mail Server v4.2 SP3 and below</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html" xml:lang="en">http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8861" xml:lang="en">8861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8889" xml:lang="en">8889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13468" xml:lang="en">mercur-auth-command-dos(13468)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.0</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.1</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1178</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:45.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2006-October/001080.html" xml:lang="en">Advanced Poll v2.02 :) &lt;= Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342493" xml:lang="en">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/448007/100/0/threaded" xml:lang="en">20061008 Advanced Poll v2.02 :) &lt;= Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8890" xml:lang="en">8890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13513" xml:lang="en">advancedpoll-php-injection(13513)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/29396" xml:lang="en">advanced-poll-comments-file-include(29396)</vuln:reference>
    </vuln:references>
    <vuln:summary>Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.0</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.1</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1179</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:46.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phpsecure.info/v2/tutos/frog/AdvancedPoll2.0.2.txt" xml:lang="en">http://www.phpsecure.info/v2/tutos/frog/AdvancedPoll2.0.2.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342493" xml:lang="en">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/440780/100/0/threaded" xml:lang="en">20060721 SolpotCrew Advisory #2 - Advanced Poll ver 2.02 (base_path) Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/19105" xml:lang="en">19105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8890" xml:lang="en">8890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.solpotcrew.org/adv/solpot-adv-02.txt" xml:lang="en">http://www.solpotcrew.org/adv/solpot-adv-02.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13514" xml:lang="en">advancedpoll-php-file-include(13514)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.0</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.1</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1180</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342493" xml:lang="en">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8890" xml:lang="en">8890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13514" xml:lang="en">advancedpoll-php-file-include(13514)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1181</vuln:cve-id>
    <vuln:published-datetime>2003-10-25T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342493" xml:lang="en">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8890" xml:lang="en">8890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13515" xml:lang="en">advancedpoll-phpinfo-obtain-information(13515)</vuln:reference>
    </vuln:references>
    <vuln:summary>Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mpm:mpm_guestbook:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mpm:mpm_guestbook:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1182</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8958" xml:lang="en">8958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13575" xml:lang="en">mpmguestbook-ing-xss(13575)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle_files:9.0.3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle_files:9.0.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle_files:9.0.3.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle_files:9.0.3.1.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle_files:9.0.3.2.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle_files:9.0.3.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1183</vuln:cve-id>
    <vuln:published-datetime>2003-10-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technology/deploy/security/pdf/2003alert60.pdf" xml:lang="en">http://www.oracle.com/technology/deploy/security/pdf/2003alert60.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8923" xml:lang="en">8923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13545" xml:lang="en">oraclecollaborationsuite-file-access(13545)</vuln:reference>
    </vuln:references>
    <vuln:summary>The WebCache component in Oracle Files 9.0.3.1.0, 9.0.3.2.0, and 9.0.3.3.0 of Oracle Collaboration Suite Release 1 caches files despite the cacheability rules imposed by Oracle Files, which allows local users to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:thwboard:thwboard:2.8_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:thwboard:thwboard:2.81_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1184</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=195009" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=195009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8959" xml:lang="en">8959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13582" xml:lang="en">thwboard-multiple-fields-xss(13582)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:thwboard:thwboard:2.8_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:thwboard:thwboard:2.81_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thwboard:thwboard:2.8_beta</vuln:product>
      <vuln:product>cpe:/a:thwboard:thwboard:2.81_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1185</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=195009" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=195009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8961" xml:lang="en">8961</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13583" xml:lang="en">thwboard-multiple-sql-injection(13583)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:telcondex:simplewebserver:2.12.30210_build3285"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:telcondex:simplewebserver:2.12.30210_build3285</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1186</vuln:cve-id>
    <vuln:published-datetime>2003-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342785" xml:lang="en">20031029 TelCondex SimpleWebserver Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8925" xml:lang="en">8925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13549" xml:lang="en">simplewebserver-referer-bo(13549)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpkit:phpkit:1.6.02"/>
        <cpe-lang:fact-ref name="cpe:/a:phpkit:phpkit:1.6.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpkit:phpkit:1.6.02</vuln:product>
      <vuln:product>cpe:/a:phpkit:phpkit:1.6.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1187</vuln:cve-id>
    <vuln:published-datetime>2003-11-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://badwebmasters.net/advisory/017/" xml:lang="en">http://badwebmasters.net/advisory/017/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013139.html" xml:lang="en">20031102 [bWM#017] Cross-Site-Scripting @ PHPKIT</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8960" xml:lang="en">8960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13590" xml:lang="en">phpkit-include-xss(13590)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:unichat:unichat:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:unichat:unichat:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1188</vuln:cve-id>
    <vuln:published-datetime>2003-11-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343182" xml:lang="en">20031102 Unichat Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8962" xml:lang="en">8962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13610" xml:lang="en">unichat-nonalphanumeric-character-dos(13610)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:nokia:ipso:3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:nokia:ipso:3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1189</vuln:cve-id>
    <vuln:published-datetime>2003-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:48.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007992" xml:lang="en">1007992</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8928" xml:lang="en">8928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13539" xml:lang="en">nokia-ipso-ipcluster-dos(13539)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.26a"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.27a"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.30"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.30a"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:1.31"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.04"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.05"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.06"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:phprecipebook:phprecipebook:2.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.24</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.25</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.26</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.26a</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.27</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.27a</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.30</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.30a</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:1.31</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.04</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.05</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.06</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.10</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.11</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.12</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.13</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.14</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.15</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.16</vuln:product>
      <vuln:product>cpe:/a:phprecipebook:phprecipebook:2.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1190</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=193940" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=193940</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8963" xml:lang="en">8963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13574" xml:lang="en">phprecipebook-recipe-xss(13574)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:e107:e107:0.545"/>
        <cpe-lang:fact-ref name="cpe:/a:e107:e107:0.603"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e107:e107:0.545</vuln:product>
      <vuln:product>cpe:/a:e107:e107:0.603</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1191</vuln:cve-id>
    <vuln:published-datetime>2003-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0313.html" xml:lang="en">20031029 E107 DoS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8930" xml:lang="en">8930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13553" xml:lang="en">e107chatboxdos(13553)</vuln:reference>
    </vuln:references>
    <vuln:summary>chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:truenorth_software:ia_webmail_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:truenorth_software:ia_webmail_server:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:truenorth_software:ia_webmail_server:3.0</vuln:product>
      <vuln:product>cpe:/a:truenorth_software:ia_webmail_server:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1192</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008075" xml:lang="en">1008075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2003-11/0001.html" xml:lang="en">20031103 IA WebMail Server 3.x Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6B002158UQ.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6B002158UQ.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8965" xml:lang="en">8965</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13580" xml:lang="en">iawebmailserver-get-bo(13580)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server_portal:3.0.9.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server_portal:9.0.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server_portal:9.0.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server_portal:9.0.2.3b"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server_portal:3.0.9.8.5</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server_portal:9.0.2.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server_portal:9.0.2.3a</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server_portal:9.0.2.3b</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1193</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/343520" xml:lang="en">20031105 Multiple SQL Injection Vulnerabilities in Oracle Application Server 9i and RDBMS (#NISR05112003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8966" xml:lang="en">8966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13593" xml:lang="en">oracle-portal-sql-injection(13593)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:booby:booby:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:booby:booby:0.1</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.1.1</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.1.2</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.1.3</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.2</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.2.1</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.2.2</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.2.3</vuln:product>
      <vuln:product>cpe:/a:booby:booby:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1194</vuln:cve-id>
    <vuln:published-datetime>2003-10-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008056" xml:lang="en">1008056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=193878" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=193878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8932" xml:lang="en">8932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13557" xml:lang="en">booby-error-message-xss(13557)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vienuke:vieboard:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:vienuke:vieboard:2.6_beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1195</vuln:cve-id>
    <vuln:published-datetime>2003-11-23T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014065.html" xml:lang="en">20031123 VieNuke VieBoard SQL Injection Vulnerability... again</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13819" xml:lang="en">vieboard-getmember-sql-injection(13819)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vienuke:vieboard:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:vienuke:vieboard:2.6_beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vienuke:vieboard:2.6</vuln:product>
      <vuln:product>cpe:/a:vienuke:vieboard:2.6_beta_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1196</vuln:cve-id>
    <vuln:published-datetime>2003-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8967" xml:lang="en">8967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13629" xml:lang="en">vieboard-viewtopic-sql-injection(13629)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ledscripts.com:ledforums:beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1197</vuln:cve-id>
    <vuln:published-datetime>2003-10-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342913" xml:lang="en">20031030 Multiple Vulnerabilities in Led-Forums</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8934" xml:lang="en">8934</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13562" xml:lang="en">ledforums-indexphp-xss(13562)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13563" xml:lang="en">ledforums-topicfield-redirect(13563)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cherokee:cherokee_httpd:0.4.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.1</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.1.5</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.1.6</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.2</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.2.5</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.2.6</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.2.7</vuln:product>
      <vuln:product>cpe:/a:cherokee:cherokee_httpd:0.4.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1198</vuln:cve-id>
    <vuln:published-datetime>2003-12-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog" xml:lang="en">http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9345" xml:lang="en">9345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14119" xml:lang="en">cherokee-post-request-dos(14119)</vuln:reference>
    </vuln:references>
    <vuln:summary>connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:myproxy:myproxy:2003-06-29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myproxy:myproxy:2003-06-29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1199</vuln:cve-id>
    <vuln:published-datetime>2004-03-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107902444305344&amp;w=2" xml:lang="en">20030311 XSS in MyProxy 20030629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9846" xml:lang="en">9846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15438" xml:lang="en">myproxy-xss(15438)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.5.2</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.7.5</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.7.9</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.8.0</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.8.1</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.8.2</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.8.3</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.8.4</vuln:product>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.8.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1200</vuln:cve-id>
    <vuln:published-datetime>2003-12-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107936753929354&amp;w=2" xml:lang="en">20040314 Rosiello Security's exploit for MDaemon</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348454" xml:lang="en">20031229 [Hat-Squad] Remote buffer overflow in Mdaemon Raw message Handler</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9317" xml:lang="en">9317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14097" xml:lang="en">mdaemon-form2raw-from-bo(14097)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11_9"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11_11"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11_11s"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openldap:openldap:2.0</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.1</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.2</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.3</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.4</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.5</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.6</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.7</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.8</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.9</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.10</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.11</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.11_9</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.11_11</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.11_11s</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.12</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.13</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.14</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.15</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.16</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.17</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.18</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.19</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.20</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.21</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.22</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.23</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.25</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.0.27</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.4</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.10</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.11</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.12</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.13</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.14</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.15</vuln:product>
      <vuln:product>cpe:/a:openldap:openldap:2.1.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1201</vuln:cve-id>
    <vuln:published-datetime>2003-03-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000685" xml:lang="en">CLSA-2003:685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-12.xml" xml:lang="en">GLSA-200403-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openldap.org/its/index.cgi?findid=2390" xml:lang="en">http://www.openldap.org/its/index.cgi?findid=2390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7656" xml:lang="en">7656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12520" xml:lang="en">openldap-back-ldbm-dos(12520)</vuln:reference>
    </vuln:references>
    <vuln:summary>ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:omail:omail_webmail:0.97.3"/>
        <cpe-lang:fact-ref name="cpe:/a:omail:omail_webmail:0.98.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omail:omail_webmail:0.97.3</vuln:product>
      <vuln:product>cpe:/a:omail:omail_webmail:0.98.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1202</vuln:cve-id>
    <vuln:published-datetime>2003-08-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106132514828641&amp;w=2" xml:lang="en">20030821 Remote Execution of Commands in Omail Webmail 0.98.4 and earlier</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106149679129042&amp;w=2" xml:lang="en">20030821 Re: Remote Execution of Commands in Omail Webmail 0.98.4 and earlier</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8451" xml:lang="en">8451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12948" xml:lang="en">omailwebmail-checklogin-code-execution(12948)</vuln:reference>
    </vuln:references>
    <vuln:summary>The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mambo:mambo_site_server:4.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mambo:mambo_site_server:4.0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1203</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html" xml:lang="en">20030318 Some XSS vulns</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7135" xml:lang="en">7135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11601" xml:lang="en">mambo-option-index-xss(11601)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mambo:mambo_site_server:4.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mambo:mambo_site_server:4.0.12_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1204</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/306206" xml:lang="en">20030110 Mambo Site Server Remote Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6571" xml:lang="en">6571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11050" xml:lang="en">mambo-multiple-scripts-xss(11050)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.12 BETA and earlier allow remote attackers to execute script on other clients via (1) the link parameter in sectionswindow.php, the directory parameter in (2) gallery.php, (3) navigation.php, or (4) uploadimage.php, the path parameter in (5) view.php, (6) the choice parameter in upload.php, (7) the sitename parameter in mambosimple.php, (8) the type parameter in upload.php, or the id parameter in (9) emailarticle.php, (10) emailfaq.php, or (11) emailnews.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:crob:crob_ftp_server:2.60.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:crob:crob_ftp_server:2.60.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1205</vuln:cve-id>
    <vuln:published-datetime>2003-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106019292611151&amp;w=2" xml:lang="en">20030806 DoS Vulnerabilities in Crob FTP Server 2.60.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.crob.net/studio/ftpserver/" xml:lang="en">http://www.crob.net/studio/ftpserver/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12838" xml:lang="en">crob-rename-file-dos(12838)</vuln:reference>
    </vuln:references>
    <vuln:summary>Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:crob:crob_ftp_server:2.60.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:crob:crob_ftp_server:2.60.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1206</vuln:cve-id>
    <vuln:published-datetime>2003-06-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:49.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106019292611151&amp;w=2" xml:lang="en">20030806 DoS Vulnerabilities in Crob FTP Server 2.60.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.crob.net/studio/ftpserver/" xml:lang="en">http://www.crob.net/studio/ftpserver/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-08/0087.html" xml:lang="en">20030807 Re: DoS Vulnerabilities in Crob FTP Server 2.60.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12834" xml:lang="en">crob-login-dos(12834)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:crob:crob_ftp_server:3.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:crob:crob_ftp_server:3.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1207</vuln:cve-id>
    <vuln:published-datetime>2004-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008908" xml:lang="en">1008908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/352329" xml:lang="en">20040201 Vulnerabilities in Crob FTP Server V3.5.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9549" xml:lang="en">9549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15105" xml:lang="en">crob-dir-dos(15105)</vuln:reference>
    </vuln:references>
    <vuln:summary>Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:enterprise_9.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:personal_9.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:standard_9.2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.2.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:enterprise_9.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:personal_9.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.1.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:standard_9.2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1208</vuln:cve-id>
    <vuln:published-datetime>2004-12-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html" xml:lang="en">20040205 Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-093.shtml" xml:lang="en">O-093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/240174" xml:lang="en">VU#240174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/399806" xml:lang="en">VU#399806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/819126" xml:lang="en">VU#819126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/846582" xml:lang="en">VU#846582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora_from_tz.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora_from_tz.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora_numtodsinterval.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora_numtodsinterval.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora_numtoyminterval.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora_numtoyminterval.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora_time_zone.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora_time_zone.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9587" xml:lang="en">9587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15060" xml:lang="en">oracle-multiple-function-bo(15060)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.1.1</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.5.2</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.6.0</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1209</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://monkeyd.sourceforge.net/Changelog.txt" xml:lang="en">http://monkeyd.sourceforge.net/Changelog.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7201" xml:lang="en">7201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11650" xml:lang="en">monkey-content-type-dos(11650)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_final"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_beta1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_final</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc2</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1210</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html" xml:lang="en">20030513 More and More SQL injection on PHP-Nuke 6.5.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7588" xml:lang="en">7588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11984" xml:lang="en">phpnuke-multiple-sql-injection(11984)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxwebportal:maxwebportal:1.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1211</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" xml:lang="en">20030606 Critical Vulnerabilities In Max Web Portal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7837" xml:lang="en">7837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12277" xml:lang="en">maxwebportal-search-xss(12277)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxwebportal:maxwebportal:1.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1212</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" xml:lang="en">20030606 Critical Vulnerabilities In Max Web Portal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7837" xml:lang="en">7837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12278" xml:lang="en">maxwebportal-form-field-modify(12278)</vuln:reference>
    </vuln:references>
    <vuln:summary>MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxwebportal:maxwebportal:1.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxwebportal:maxwebportal:1.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1213</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" xml:lang="en">20030606 Critical Vulnerabilities In Max Web Portal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7837" xml:lang="en">7837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12279" xml:lang="en">maxwebportal-database-access(12279)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.40"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.41"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.42"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.43"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.44"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.45"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.45b"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.40</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.41</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.42</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.43</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.44</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.45</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.45b</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0.1</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0.2</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc1</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc2</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1214</vuln:cve-id>
    <vuln:published-datetime>2004-02-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ezcontents.org/forum/viewtopic.php?t=361" xml:lang="en">http://www.ezcontents.org/forum/viewtopic.php?t=361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15136" xml:lang="en">ezcontents-login-bypass(15136)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.0.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.2.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.2.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.4</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.3</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.4</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.5</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.6</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_beta1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc3</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1215</vuln:cve-id>
    <vuln:published-datetime>2003-12-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107273069130885&amp;w=2" xml:lang="en">20031229 SQL Injection in phpBB's groupcp.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943" xml:lang="en">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9314" xml:lang="en">9314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14096" xml:lang="en">phpbb-groupcp-sql-injection(14096)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0_rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.0.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.2.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.2.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.4</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.3</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.4</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.5</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.6</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_beta1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc3</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0_rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1216</vuln:cve-id>
    <vuln:published-datetime>2003-11-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106997132425576&amp;w=2" xml:lang="en">20031127 phpBB 2.06 search.php SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107005608726609&amp;w=2" xml:lang="en">20031128 [Hat-Squad] phpBB search_id injection exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107196735102970&amp;w=2" xml:lang="en">20031220 phpBB v2.06 search_id sql injection exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpbb.com/phpBB/viewtopic.php?t=153818" xml:lang="en">http://www.phpbb.com/phpBB/viewtopic.php?t=153818</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9122" xml:lang="en">9122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13867" xml:lang="en">phpbb-searchphp-sql-injection(13867)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1217">
    <vuln:cve-id>CVE-2003-1217</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.387-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.387-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1218">
    <vuln:cve-id>CVE-2003-1218</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:01.400-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:01.400-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oscommerce:oscommerce:2.2_ms2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oscommerce:oscommerce:2.2_ms2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1219</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-12-12T21:24:28.620-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://osdir.com/ml/web.oscommerce.cvs/2003-12/msg00024.html" xml:lang="en">[tep-commits] 20031217 [TEP-COMMIT] CVS: catalog/catalog/includes/functions html_output.php,1.58,1.59</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oscommerce.com/community/bugs,1546" xml:lang="en">http://www.oscommerce.com/community/bugs,1546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/347831" xml:lang="en">20031217 osCommerce Malformed Session ID XSS Vuln</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9238" xml:lang="en">9238</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1220</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:38.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-01T17:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/25" xml:lang="en">BEA03-39.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9034" xml:lang="en">9034</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1221</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:38.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-02T09:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/32" xml:lang="en">BEA03-40.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9034" xml:lang="en">9034</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1222</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:39.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-02T09:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/63" xml:lang="en">BEA03-41.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9034" xml:lang="en">9034</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1223">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1223</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:43.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-02T09:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/48" xml:lang="en">BEA03-42.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9034" xml:lang="en">9034</vuln:reference>
    </vuln:references>
    <vuln:summary>The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1224</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:43.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-02T09:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/22" xml:lang="en">BEA03-30.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7563" xml:lang="en">7563</vuln:reference>
    </vuln:references>
    <vuln:summary>Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1225</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:43.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-06T13:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/22" xml:lang="en">BEA03-30.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7563" xml:lang="en">7563</vuln:reference>
    </vuln:references>
    <vuln:summary>The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1226">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1226</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:22:43.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-02T13:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/22" xml:lang="en">BEA03-30.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7563" xml:lang="en">7563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7587" xml:lang="en">7587</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1227">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:1.4_pl1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gallery_project:gallery:1.4</vuln:product>
      <vuln:product>cpe:/a:gallery_project:gallery:1.4_pl1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1227</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341044" xml:lang="en">20031011 Gallery 1.4 including file vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341094" xml:lang="en">20031011 RE: Gallery 1.4 including file vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341098" xml:lang="en">20031012 Re: Gallery 1.4 including file vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8814" xml:lang="en">8814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13419" xml:lang="en">gallery-indexphp-file-include(13419)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.  NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1228">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p4"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p5"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p6"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p7"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p8"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p17"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.3_p18"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.4_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:mathopd:mathopd:1.5_b13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mathopd:mathopd:1.2</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p4</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p5</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p6</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p7</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p8</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p17</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.3_p18</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.4</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.4_p1</vuln:product>
      <vuln:product>cpe:/a:mathopd:mathopd:1.5_b13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1228</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107064887507504&amp;w=2" xml:lang="en">20031205 [Fwd: Security Alert; possible buffer overflow in all Mathopd versions]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107090601705839&amp;w=2" xml:lang="en">20031208 Re: [Fwd: Security Alert; possible buffer overflow in all Mathopd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/5FP0C1FCAW.html" xml:lang="en">http://www.securiteam.com/unixfocus/5FP0C1FCAW.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9871" xml:lang="en">9871</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/15474" xml:lang="en">mathopd-preparereply-bo(15474)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1229">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:java_web_start:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_web_start:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_web_start:1.0.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_web_start:1.0.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_web_start:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01a::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3_02::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3_05::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.0_02::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.0_02::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.0_02::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.1::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update1:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1:solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1a:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.0_02::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.0_02::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.0_02::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.1::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jsse:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1229</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:18.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5883" name="oval:org.mitre.oval:def:5883"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0334.html" xml:lang="en">20030128 Incorrect Certificate Validation in Java Secure Socket Extension</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://java.sun.com/products/jsse/CHANGES.txt" xml:lang="en">http://java.sun.com/products/jsse/CHANGES.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006007" xml:lang="en">1006007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007483" xml:lang="en">1007483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1" xml:lang="en">50081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6682" xml:lang="en">6682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006001" xml:lang="en">1006001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0301-239" xml:lang="en">HPSBUX0301-239</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11182" xml:lang="en">sun-java-improper-validation(11182)</vuln:reference>
    </vuln:references>
    <vuln:summary>X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1230">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:release"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1230</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5013" xml:lang="en">FreeBSD-SA-03:03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6920" xml:lang="en">6920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11397" xml:lang="en">freebsd-syncookie-brute-force(11397)</vuln:reference>
    </vuln:references>
    <vuln:summary>The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1231">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ecw-shop:ecw-shop:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:ecw-shop:ecw-shop:5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ecw-shop:ecw-shop:5.01</vuln:product>
      <vuln:product>cpe:/a:ecw-shop:ecw-shop:5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1231</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008522" xml:lang="en">1008522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/6D00F2A95C.html" xml:lang="en">http://www.securiteam.com/unixfocus/6D00F2A95C.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9244" xml:lang="en">9244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/14032" xml:lang="en">ecwshop-cat-xss(14032)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1232">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:emacs:21.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:emacs:21.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1232</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:13:42.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-26T16:08:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://groups.google.com/group/gnu.emacs.bug/browse_frm/thread/9424ec1b2fdae321/c691a2da8904db0f?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;rnum=1&amp;prev=/groups%3Fq%3Dguninski%2Bemacs%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3Dmailman.763.1041357806.19936.bug-gnu-emacs%2540gnu.org%26rnum%3D1#c691a2da8904db0f" xml:lang="en">http://groups.google.com/group/gnu.emacs.bug/browse_frm/thread/9424ec1b2fdae321/c691a2da8904db0f?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;rnum=1&amp;prev=/groups%3Fq%3Dguninski%2Bemacs%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3Dmailman.763.1041357806.19936.bug-gnu-emacs%2540gnu.org%26rnum%3D1#c691a2da8904db0f</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html" xml:lang="en">http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:208" xml:lang="en">MDKSA-2005:208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/15375" xml:lang="en">15375</vuln:reference>
    </vuln:references>
    <vuln:summary>Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1233">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pedestal_software:integrity_protection_driver:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pedestal_software:integrity_protection_driver:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pedestal_software:integrity_protection_driver:1.2</vuln:product>
      <vuln:product>cpe:/a:pedestal_software:integrity_protection_driver:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1233</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html" xml:lang="en">20030103 Pedestal Software Security Notice</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html" xml:lang="en">20030103 Another way to bypass Integrity Protection Driver ('subst' vuln)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phrack.org/show.php?p=59&amp;a=16" xml:lang="en">http://www.phrack.org/show.php?p=59&amp;a=16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6511" xml:lang="en">6511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/10979" xml:lang="en">ipd-ntcreatesymboliclinkobject-subs-symlink(10979)</vuln:reference>
    </vuln:references>
    <vuln:summary>Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1234">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2:current"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release_p8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:release_p3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2:current</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:release_p8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:release_p3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1234</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:46.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:44.filedesc.asc" xml:lang="en">FreeBSD-SA-02:44</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0057.html" xml:lang="en">20030107 FreeBSD Security Advisory FreeBSD-SA-02:44.filedesc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0006.html" xml:lang="en">20030106 PDS: Integer overflow in FreeBSD kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10993.php" xml:lang="en">freebsd-kernel-integer-overflow(10993)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pine.nl/press/pine-cert-20030101.txt" xml:lang="en">http://www.pine.nl/press/pine-cert-20030101.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305308/30/26420/threaded" xml:lang="en">20030106 PDS: Integer overflow in FreeBSD kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6524" xml:lang="en">6524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005898" xml:lang="en">1005898</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1235">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:brs:webweaver:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1235</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:24.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T10:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-04/0014.html" xml:lang="en">20030331 BRS WebWeaver: full disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11686.php" xml:lang="en">webweaver-testcgi-info-disclosure(11686)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7283" xml:lang="en">7283</vuln:reference>
    </vuln:references>
    <vuln:summary>BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current working directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1236">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tanne:tanne:0.6.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tanne:tanne:0.6.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1236</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:24.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T10:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0011.html" xml:lang="en">20030107 [INetCop Security Advisory] Remote format string vulnerability in Tanne.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2" xml:lang="en">http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11006.php" xml:lang="en">tanne-logger-format-string(11006)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305460" xml:lang="en">20030107 [INetCop Security Advisory] Remote format string vulnerability in    Tanne.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305663" xml:lang="en">20030108 Tanne Remote format string exploit (Proof of Concept)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6553" xml:lang="en">6553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005900" xml:lang="en">1005900</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1237">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:matt_wright:wwwboard:2.0a2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:matt_wright:wwwboard:2.0a2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1237</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:24.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T10:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0274.html" xml:lang="en">20030222 [SCSA-007] Cross Site Scripting Vulnerabilities in WWWBoard</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11383.php" xml:lang="en">wwwboard-message-xss(11383)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6918" xml:lang="en">6918</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1238">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2_beta</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1238</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:24.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T10:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html" xml:lang="en">20030221 [SCSA-006] XSS &amp; Function Execution Vulnerabilities in Nuked-Klan</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html" xml:lang="en">20030318 Some XSS vulns</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11420.php" xml:lang="en">nuked-klan-team-xss(11420)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6916" xml:lang="en">6916</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1239">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wihphoto:wihphoto:0.86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wihphoto:wihphoto:0.86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1239</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:24.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T10:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html" xml:lang="en">20030223 WihPhoto (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11429.php" xml:lang="en">wihphoto-sendphoto-file-disclosure(11429)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312966" xml:lang="en">20030223 WihPhoto (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6929" xml:lang="en">6929</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1240">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cutephp:cutenews:0.88"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cutephp:cutenews:0.88</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1240</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:25.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T11:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0320.html" xml:lang="en">20030225 PHP code injection in CuteNews</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11417.php" xml:lang="en">cutenews-php-file-include(11417)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6935" xml:lang="en">6935</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1241">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:levcgi.com:myguestbook:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:levcgi.com:myguestbook:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1241</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:25.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T09:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0089.html" xml:lang="en">20030221 Myguestbook (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312762" xml:lang="en">20030221 Myguestbook (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6906" xml:lang="en">6906</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1242">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sage:sage:1.0_beta_3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1242</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:25.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0236.html" xml:lang="en">20030219 XSS and Path Disclosure in Sage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11372.php" xml:lang="en">sage-module-path-disclosure(11372)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6893" xml:lang="en">6893</vuln:reference>
    </vuln:references>
    <vuln:summary>Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1243">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sage:sage:1.0_beta_3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1243</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:50.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0236.html" xml:lang="en">20030219 XSS and Path Disclosure in Sage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6894" xml:lang="en">6894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11371" xml:lang="en">sage-mod-xss(11371)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1244">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1244</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:25.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0245.html" xml:lang="en">20030220 phpBB Security Bugs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11376.php" xml:lang="en">phpbb-pageheader-sql-injection(11376)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6888" xml:lang="en">6888</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1245">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mambo:mambo_site_server:4.0.12_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1245</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0302.html" xml:lang="en">20030224 Mambo SiteServer exploit gains administrative privileges</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6926" xml:lang="en">6926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11398" xml:lang="en">mambo-sessionid-gain-privileges(11398)</vuln:reference>
    </vuln:references>
    <vuln:summary>index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1246">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pedestal_software:integrity_protection_driver:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pedestal_software:integrity_protection_driver:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pedestal_software:integrity_protection_driver:1.2</vuln:product>
      <vuln:product>cpe:/a:pedestal_software:integrity_protection_driver:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1246</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:25.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html" xml:lang="en">20030103 Pedestal Software Security Notice</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html" xml:lang="en">20030103 Another way to bypass Integrity Protection Driver ('subst' vuln)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10979.php" xml:lang="en">ipd-ntcreatesymboliclinkobject-subs-symlink(10979)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6511" xml:lang="en">6511</vuln:reference>
    </vuln:references>
    <vuln:summary>NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1247">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.3_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.3_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1247</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://psoft.net/misc/webshell_patch.html" xml:lang="en">http://psoft.net/misc/webshell_patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10999.php" xml:lang="en">hsphere-webshell-readfile-bo(10999)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11002.php" xml:lang="en">hsphere-webshell-diskusage-bo(11002)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11003.php" xml:lang="en">hsphere-webshell-flist-bo(11003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305313" xml:lang="en">20030106 Remote root vuln in HSphere WebShell</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6527" xml:lang="en">6527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6537" xml:lang="en">6537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6538" xml:lang="en">6538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6540" xml:lang="en">6540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005893" xml:lang="en">1005893</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1248">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.3_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.3_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1248</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://psoft.net/misc/webshell_patch.html" xml:lang="en">http://psoft.net/misc/webshell_patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11001.php" xml:lang="en">hsphere-webshell-encodefilename-execution(11001)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305313" xml:lang="en">20030106 Remote root vuln in HSphere WebShell</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6537" xml:lang="en">6537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6539" xml:lang="en">6539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005893" xml:lang="en">1005893</vuln:reference>
    </vuln:references>
    <vuln:summary>H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1249">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:webintelligence:2.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:businessobjects:webintelligence:2.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1249</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0014.html" xml:lang="en">20030109 WebIntelligence session hijacking vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11026.php" xml:lang="en">webintelligence-session-hijacking(11026)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305991" xml:lang="en">20030109 WebIntelligence session hijacking vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6569" xml:lang="en">6569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005906" xml:lang="en">1005906</vuln:reference>
    </vuln:references>
    <vuln:summary>WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1250">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:efficient_networks:5861_dsl_router:5.3.80_firmware"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:efficient_networks:5861_dsl_router:5.3.80_firmware</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1250</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.543-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0015.html" xml:lang="en">20030110 Efficient Networks 5861 DSL Router</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1005980" xml:lang="en">1005980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11032.php" xml:lang="en">efficient-dsl-portscan-dos(11032)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/306081" xml:lang="en">20030110 Efficient Networks 5861 DSL Router</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308008" xml:lang="en">20030123 5861 IP Filtering issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6573" xml:lang="en">6573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005910" xml:lang="en">1005910</vuln:reference>
    </vuln:references>
    <vuln:summary>Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN packets to the WAN interface using a port scanner such as nmap.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1251">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nx:n_x_web_content_management_system_2002:prerelease1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nx:n_x_web_content_management_system_2002:prerelease1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1251</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0005.html" xml:lang="en">20030102 N/X (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10969.php" xml:lang="en">nx-file-include(10969)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6500" xml:lang="en">6500</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1252">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kelli_shaver:s8forum:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kelli_shaver:s8forum:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1252</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T13:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0004.html" xml:lang="en">20030105 A security vulnerability in S8Forum</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10974.php" xml:lang="en">s8forum-register-command-execution(10974)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305406" xml:lang="en">20030105 A security vulnerability in S8Forum</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6547" xml:lang="en">6547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005881" xml:lang="en">1005881</vuln:reference>
    </vuln:references>
    <vuln:summary>register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1253">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sangwan_kim:bookmark4u:1.8.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sangwan_kim:bookmark4u:1.8.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1253</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:26.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-18T15:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" xml:lang="en">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11009.php" xml:lang="en">bookmark4u-file-include(11009)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1254">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:active_php_bookmarks:active_php_bookmarks:1.1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1254</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:27.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-18T15:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" xml:lang="en">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11010.php" xml:lang="en">apb-apbsettings-file-include(11010)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6545" xml:lang="en">6545</vuln:reference>
    </vuln:references>
    <vuln:summary>Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1255">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:active_php_bookmarks:active_php_bookmarks:1.1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:active_php_bookmarks:active_php_bookmarks:1.1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1255</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" xml:lang="en">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6546" xml:lang="en">6546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11011" xml:lang="en">apb-addbookmark-authentication-bypass(11011)</vuln:reference>
    </vuln:references>
    <vuln:summary>add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1256">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:e-theni:e-theni"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e-theni:e-theni</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1256</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:27.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-18T15:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.html" xml:lang="en">20030106 E-theni (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11013.php" xml:lang="en">etheni-afflistelangue-file-include(11013)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305381" xml:lang="en">20030106 E-theni (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6970" xml:lang="en">6970</vuln:reference>
    </vuln:references>
    <vuln:summary>aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1257">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:e-theni:e-theni"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e-theni:e-theni</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1257</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:27.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-18T15:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.html" xml:lang="en">20030106 E-theni (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11012.php" xml:lang="en">etheni-findthenihome-information-disclosure(11012)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305381" xml:lang="en">20030106 E-theni (PHP)</vuln:reference>
    </vuln:references>
    <vuln:summary>find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1258">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:versatilebulletinboard:versatilebulletinboard:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:versatilebulletinboard:versatilebulletinboard:0.9.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:versatilebulletinboard:versatilebulletinboard:0.9.5</vuln:product>
      <vuln:product>cpe:/a:versatilebulletinboard:versatilebulletinboard:0.9.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1258</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:27.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-18T15:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0017.html" xml:lang="en">20030110 vulnerability in versatile BulletinBoard  Allows Gaining Administrative Privileges.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11044.php" xml:lang="en">vbb-unauthorized-privileges(11044)</vuln:reference>
    </vuln:references>
    <vuln:summary>activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1259">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:globalscape:cuteftp:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:globalscape:cuteftp:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1259</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:27.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0026.html" xml:lang="en">20030104 CuteFTP: buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10984.php" xml:lang="en">cuteftp-ftp-banner-bo(10984)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/325659" xml:lang="en">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6518" xml:lang="en">6518</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1260">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:globalscape:cuteftp:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:globalscape:cuteftp:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1260</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:28.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0123.html" xml:lang="en">20030118 CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0087.html" xml:lang="en">20030205 Re: CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/lists/fulldisclosure/2003/Jan/0126.html" xml:lang="en">20030107 CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11093.php" xml:lang="en">cuteftp-list-command-bo(11093)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/325659" xml:lang="en">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6642" xml:lang="en">6642</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1261">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:globalscape:cuteftp:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:globalscape:cuteftp:5.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:globalscape:cuteftp:5.0</vuln:product>
      <vuln:product>cpe:/a:globalscape:cuteftp:5.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1261</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:28.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0087.html" xml:lang="en">20030205 Re: CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11275.php" xml:lang="en">cuteftp-url-clipboard-bo(11275)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310710" xml:lang="en">20030206 Re: CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/325659" xml:lang="en">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6786" xml:lang="en">6786</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1262">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:http_fetcher:http_fetcher_library:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:http_fetcher:http_fetcher_library:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:http_fetcher:http_fetcher_library:1.0.0</vuln:product>
      <vuln:product>cpe:/a:http_fetcher:http_fetcher_library:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1262</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:39:36.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104195613529429&amp;w=2" xml:lang="en">20030107 GLSA:  http-fetcher</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11000.php" xml:lang="en">http-fetcher-httpfetch-bo(11000)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/content/view/104480/104/" xml:lang="en">GLSA-200301-6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305340" xml:lang="en">20030106 [INetCop Security Advisory] Buffer Overflow vulnerability in HTTP Fetcher Library.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6531" xml:lang="en">6531</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a long (1) host, (2) referer, or (3) userAgent value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1263">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:brown_bear_software:ical:3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brown_bear_software:ical:3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1263</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:28.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0011.html" xml:lang="en">20030103 ical 3.7 remote dos</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10973.php" xml:lang="en">ical-icalexe-port-dos(10973)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6505" xml:lang="en">6505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6506" xml:lang="en">6506</vuln:reference>
    </vuln:references>
    <vuln:summary>ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1264">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:d-link:di-614%2b:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:longshine_technologie:longshine_wireless_ethernet_access_point:lcs-883r-ac-b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:d-link:di-614%2b:2.0</vuln:product>
      <vuln:product>cpe:/h:longshine_technologie:longshine_wireless_ethernet_access_point:lcs-883r-ac-b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1264</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:28.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10997.php" xml:lang="en">longshine-ap-tftp-access(10997)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305344" xml:lang="en">20030106 Longshine WLAN Access-Point LCS-883R VU#310201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305391" xml:lang="en">20030106 Re: Longshine WLAN Access-Point LCS-883R VU#310201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6533" xml:lang="en">6533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005897" xml:lang="en">1005897</vuln:reference>
    </vuln:references>
    <vuln:summary>TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1265">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:5.0</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1265</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:28.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2002-12/0277.html" xml:lang="en">20030101 Potential disclosure of sensitive information in Netscape 7.0 email client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10963.php" xml:lang="en">netscape-email-deletion-failure(10963)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6499" xml:lang="en">6499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005871" xml:lang="en">1005871</vuln:reference>
    </vuln:references>
    <vuln:summary>Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1266">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.92"/>
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.93"/>
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.94"/>
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.95"/>
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.96"/>
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.97"/>
        <cpe-lang:fact-ref name="cpe:/a:etype:eserv:2.98"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:etype:eserv:2.92</vuln:product>
      <vuln:product>cpe:/a:etype:eserv:2.93</vuln:product>
      <vuln:product>cpe:/a:etype:eserv:2.94</vuln:product>
      <vuln:product>cpe:/a:etype:eserv:2.95</vuln:product>
      <vuln:product>cpe:/a:etype:eserv:2.96</vuln:product>
      <vuln:product>cpe:/a:etype:eserv:2.97</vuln:product>
      <vuln:product>cpe:/a:etype:eserv:2.98</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1266</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:28.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T09:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0022.html" xml:lang="en">20030104 EServ/2.97 remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10975.php" xml:lang="en">eserv-remote-data-dos(10975)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6519" xml:lang="en">6519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6520" xml:lang="en">6520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6521" xml:lang="en">6521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6522" xml:lang="en">6522</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1267">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:steve_poulsen:guildftpd:0.999"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:steve_poulsen:guildftpd:0.999</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1267</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:29.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T10:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10964.php" xml:lang="en">guildftpd-aux-port-dos(10964)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/5SP030A8UO.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/5SP030A8UO.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005864" xml:lang="en">1005864</vuln:reference>
    </vuln:references>
    <vuln:summary>GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1268">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:urlogy:a.shop.kart:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:urlogy:a.shop.kart:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1268</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:29.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T14:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.centaura.com.ar/infosec/adv/ashopkart.txt" xml:lang="en">http://www.centaura.com.ar/infosec/adv/ashopkart.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11029.php" xml:lang="en">ashopkart-multiple-sql-injection(11029)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305685" xml:lang="en">20030108 a.shopKart Shopping Cart remote vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6558" xml:lang="en">6558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005903" xml:lang="en">1005903</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1269">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:an:an-http:1.41e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:an:an-http:1.41e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1269</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:29.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-19T14:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10976.php" xml:lang="en">an-http-path-disclosure(10976)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305234" xml:lang="en">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6528" xml:lang="en">6528</vuln:reference>
    </vuln:references>
    <vuln:summary>AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1270">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:an:an-http:1.41e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:an:an-http:1.41e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1270</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:29.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T08:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10978.php" xml:lang="en">an-http-script-dos(10978)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305234" xml:lang="en">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</vuln:reference>
    </vuln:references>
    <vuln:summary>AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1271">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:an:an-http:1.41e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:an:an-http:1.41e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1271</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:29.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T09:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10977.php" xml:lang="en">an-http-script-xss(10977)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305234" xml:lang="en">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6529" xml:lang="en">6529</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1272">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nullsoft:winamp:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1272</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" xml:lang="en">20030104 WinAmp v.3.0: buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10980.php" xml:lang="en">winamp-b4s-playlistname-bo(10980)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6515" xml:lang="en">6515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6516" xml:lang="en">6516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/10981" xml:lang="en">winamp-b4s-path-bo(10981)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1273">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nullsoft:winamp:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1273</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" xml:lang="en">20030104 WinAmp v.3.0: buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6517" xml:lang="en">6517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/10982" xml:lang="en">winamp-b4s-playlistname-dos(10982)</vuln:reference>
    </vuln:references>
    <vuln:summary>Winamp 3.0 allows remote attackers to cause a denial of service (crash) via a .b4s file with a playlist name that contains some non-English characters, e.g. Cyrillic characters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1274">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:winamp:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nullsoft:winamp:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1274</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" xml:lang="en">20030104 WinAmp v.3.0: buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/10983" xml:lang="en">winamp-b4s-path-dos(10983)</vuln:reference>
    </vuln:references>
    <vuln:summary>Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1275">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:pocket_ie:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:pocket_ie:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1275</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:30.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0013.html" xml:lang="en">20030103 JS Bug makes it possible to deliberately crash Pocket PC IE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11004.php" xml:lang="en">pie-javascript-objectinnerhtml-dos(11004)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6507" xml:lang="en">6507</vuln:reference>
    </vuln:references>
    <vuln:summary>Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1276">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nettelephone:nettelephone:3.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nettelephone:nettelephone:3.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1276</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:30.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0046.html" xml:lang="en">20030103 Multiple Issues in Nettelephone Dialer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11007.php" xml:lang="en">nettelephone-insecure-account-information(11007)</vuln:reference>
    </vuln:references>
    <vuln:summary>Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry key, which could allow local users to gain unauthorized access to NetTelephone accounts.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1277">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yabb:yabb:1.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yabb:yabb:1.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1277</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:30.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10989.php" xml:lang="en">yabb-newstemplate-xss(10989)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10990.php" xml:lang="en">yabb-se-index-xss(10990)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/5BP051F8VE.html" xml:lang="en">http://www.securiteam.com/unixfocus/5BP051F8VE.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/5BP061F8US.html" xml:lang="en">http://www.securiteam.com/unixfocus/5BP061F8US.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html</vuln:summary>
  </entry>
  <entry id="CVE-2003-1278">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:infopop:opentopic:2.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:infopop:opentopic:2.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1278</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:30.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10985.php" xml:lang="en">opentopic-img-xss(10985)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305232" xml:lang="en">20030104 OpenTopic security hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6523" xml:lang="en">6523</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1279">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:insightful:s-plus:6.0::unix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1279</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:30.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11005.php" xml:lang="en">splus-tmp-file-symlink(11005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305342" xml:lang="en">20030105 S-plus /tmp usage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6530" xml:lang="en">6530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005896" xml:lang="en">1005896</vuln:reference>
    </vuln:references>
    <vuln:summary>S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1280">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eekim:cgihtml:1.69"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eekim:cgihtml:1.69</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1280</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:31.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11022.php" xml:lang="en">cgihtml-dotdot-directory-traversal(11022)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305469" xml:lang="en">20030107 Multiple cgihtml vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6550" xml:lang="en">6550</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1281">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eekim:cgihtml:1.69"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eekim:cgihtml:1.69</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1281</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:31.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11023.php" xml:lang="en">cgihtml-tmpfile-symlink(11023)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/305469" xml:lang="en">20030107 Multiple cgihtml vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6552" xml:lang="en">6552</vuln:reference>
    </vuln:references>
    <vuln:summary>cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1282">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:net.data"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1282</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:31.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11016.php" xml:lang="en">ibm-netdata-view-variables(11016)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/5CP061F8VS.html" xml:lang="en">http://www.securiteam.com/securitynews/5CP061F8VS.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005890" xml:lang="en">1005890</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1283">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kazaa:kazaa_media_desktop:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kazaa:kazaa_media_desktop:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1283</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:31.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-20T10:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0056.html" xml:lang="en">20030107 KaZaA - Bad Zone</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11031.php" xml:lang="en">kazaa-ad-local-zone(11031)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6543" xml:lang="en">6543</vuln:reference>
    </vuln:references>
    <vuln:summary>KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1284">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1284</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007819" xml:lang="en">1007819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20030925 Sambar Server Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sambar.com/security.htm" xml:lang="en">http://www.sambar.com/security.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13305" xml:lang="en">sambar-multiple-vulnerabilities(13305)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1285">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta5</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta6</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta5</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1285</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007819" xml:lang="en">1007819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20030925 Sambar Server Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sambar.com/security.htm" xml:lang="en">http://www.sambar.com/security.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13305" xml:lang="en">sambar-multiple-vulnerabilities(13305)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16056" xml:lang="en">sambar-multiple-xss(16056)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3) environ.pl, (4) the query parameter to samples/search.dll, (5) the price parameter to mortgage.pl, (6) the query string in dumpenv.pl, (7) the query string to dumpenv.pl, and (8) the E-Mail field of the guestbook script (book.pl).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1286">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta5</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta6</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta5</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1286</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html" xml:lang="en">20040430 SECURITY.NNOV: Sambar security quest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007819" xml:lang="en">1007819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20030925 Sambar Server Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sambar.com/security.htm" xml:lang="en">http://www.sambar.com/security.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10256" xml:lang="en">10256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16054" xml:lang="en">sambar-http-gain-access(16054)</vuln:reference>
    </vuln:references>
    <vuln:summary>HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1287">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.1:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta5</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.0:beta6</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta4</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.1:beta5</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.2</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:5.3</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta1</vuln:product>
      <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1287</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-10T21:29:51.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html" xml:lang="en">20040430 SECURITY.NNOV: Sambar security quest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007819" xml:lang="en">1007819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20030925 Sambar Server Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sambar.com/security.htm" xml:lang="en">http://www.sambar.com/security.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/16059" xml:lang="en">sambar-post-code-execution(16059)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1288">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vserver:linux-vserver:1.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1288</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:32.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-06-15T14:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux-vserver.org/ChangeLog" xml:lang="en">http://linux-vserver.org/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://list.linux-vserver.org/archive/vserver/msg05630.html" xml:lang="en">[Vserver] 20031218 SMP oops 2.4.23 v1.22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://list.linux-vserver.org/archive/vserver/msg05631.html" xml:lang="en">[Vserver] 20031219 Re: SMP oops 2.4.23 v1.22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://list.linux-vserver.org/archive/vserver/msg05658.html" xml:lang="en">[Vserver] 20031220 Re: SMP oops 2.4.23 v1.22</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and (e) vc_new_s_context functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1289">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:release_p2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release_p1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1289</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-19T21:29:01.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:10.ibcs2.asc" xml:lang="en">FreeBSD-SA-03:10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007460" xml:lang="en">1007460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12892" xml:lang="en">freebsd-ibcs2-kernel-memory(12892)</vuln:reference>
    </vuln:references>
    <vuln:summary>The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1290">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp6:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp5:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp5:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp3:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4:win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp6:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp5:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp5:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp3:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4:win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1290</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-19T21:29:01.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/162" xml:lang="en">BEA03-43.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16215" xml:lang="en">16215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9034" xml:lang="en">9034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13752" xml:lang="en">weblogic-mbeanhome-obtain-information(13752)</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1291">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:1.5.2:patch1"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:1.5.2:patch2"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:1.5.2:patch3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:vmware:esx:1.5.2:patch1</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:1.5.2:patch2</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:1.5.2:patch3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1291</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:23.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/download/esx/esx152-patch4.html" xml:lang="en">http://www.vmware.com/download/esx/esx152-patch4.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/kb/enduser/std_adp.php?p_sid=dsxk*BWh&amp;p_lva=&amp;p_faqid=1108" xml:lang="en">http://www.vmware.com/support/kb/enduser/std_adp.php?p_sid=dsxk*BWh&amp;p_lva=&amp;p_faqid=1108</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1292">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ashwebstudio:ashnews:0.83"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ashwebstudio:ashnews:0.83</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1292</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:18.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0969.html" xml:lang="en">20060130 Re: ashnews Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0979.html" xml:lang="en">20060131 Re: ashnews Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0980.html" xml:lang="en">20060131 Re: ashnews Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://forums.ashwebstudio.com/viewtopic.php?t=353&amp;start=0" xml:lang="en">http://forums.ashwebstudio.com/viewtopic.php?t=353&amp;start=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/329910" xml:lang="en">20030720 sorry, wrong file</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16436" xml:lang="en">16436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18248" xml:lang="en">18248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/1864" xml:lang="en">1864</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1293">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nukedweb:guestbookhost"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nukedweb:guestbookhost</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1293</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:33.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-07T12:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/326506" xml:lang="en">20030724 GuestBookHost : Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8025" xml:lang="en">8025</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1294">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.05_5cl"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.05_6"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.05_6a"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.05_150"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.07_2"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.08_29135cl"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.09_0"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.10_4"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.10_6"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.10_8"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.10_15"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.11_0"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.12_58"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.12_62"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.14_0"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.14_2"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.14_4"/>
        <cpe-lang:fact-ref name="cpe:/a:xscreensaver:xscreensaver:4.14_5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.05_5cl</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.05_6</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.05_6a</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.05_150</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.07_2</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.08_29135cl</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.09_0</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.10_4</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.10_6</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.10_8</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.10_15</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.11_0</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.12_58</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.12_62</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.14_0</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.14_2</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.14_4</vuln:product>
      <vuln:product>cpe:/a:xscreensaver:xscreensaver:4.14_5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1294</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:19.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10848" name="oval:org.mitre.oval:def:10848"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" xml:lang="en">20060602-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jwz.livejournal.com/310943.html" xml:lang="en">http://jwz.livejournal.com/310943.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/download/updates/90_i386.html" xml:lang="en">http://www.novell.com/linux/download/updates/90_i386.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0498.html" xml:lang="en">RHSA-2006:0498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9125" xml:lang="en">9125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1948" xml:lang="en">ADV-2006-1948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=124968" xml:lang="en">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=124968</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286</vuln:reference>
    </vuln:references>
    <vuln:summary>Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1295">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1295</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:33.713-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-01T11:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/download/updates/90_i386.html" xml:lang="en">http://www.novell.com/linux/download/updates/90_i386.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9125" xml:lang="en">9125</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1296">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:efs_software:efs_web_server:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1296</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-19T21:29:01.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0083.html" xml:lang="en">20031004 Vulnerabilities in Easy File Sharing Web Server (1.2 NEW)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13360" xml:lang="en">easyfilesharing-title-dos(13360)</vuln:reference>
    </vuln:references>
    <vuln:summary>Easy File Sharing (EFS) Web Server 1.2 allows remote authenticated users to cause a denial of service via (1) an "empty symbol" in the Title field or (2) certain data in the Your Message field, possibly a long argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1297">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:efs_software:efs_web_server:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1297</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:34.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-01T11:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0083.html" xml:lang="en">20031004 Vulnerabilities in Easy File Sharing Web Server (1.2 NEW)</vuln:reference>
    </vuln:references>
    <vuln:summary>Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obtain sensitive information including an SMTP account username and password hash, the server configuration, and server log files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1298">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:anyportal_php:anyportal_php:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:anyportal_php:anyportal_php:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1298</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-19T21:29:01.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://nger.org/anyportal/forum/read.php?f=1&amp;i=152&amp;t=152#reply_152" xml:lang="en">http://nger.org/anyportal/forum/read.php?f=1&amp;i=152&amp;t=152#reply_152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17197" xml:lang="en">17197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1053" xml:lang="en">ADV-2006-1053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/25396" xml:lang="en">anyportalphp-siteman-directory-traversal(25396)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with "./.." (dot slash dot dot).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1299">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pablo_software_solutions:baby_ftp_server:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pablo_software_solutions:baby_ftp_server:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1299</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-11-28T14:06:24.817-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0305-exploits/baby.txt" xml:lang="en">http://packetstormsecurity.org/0305-exploits/baby.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html" xml:lang="en">http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7749" xml:lang="en">7749</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1300">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pablo_software_solutions:baby_ftp_server:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pablo_software_solutions:baby_ftp_server:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1300</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:34.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-06-15T14:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0305-exploits/baby.txt" xml:lang="en">http://packetstormsecurity.org/0305-exploits/baby.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html" xml:lang="en">http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1301">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1301</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:21.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4396719" xml:lang="en">http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4396719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4944300" xml:lang="en">http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4944300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.illegalaccess.org/exploit/ObjectStackOverflow.html" xml:lang="en">http://www.illegalaccess.org/exploit/ObjectStackOverflow.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/434705/100/0/threaded" xml:lang="en">20060521 Generic Browser Crash with Java 1.4.2_11, Java 1.5.0_06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18058" xml:lang="en">18058</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1302">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1302</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-06-15T12:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.php.net/bug.php?id=22048" xml:lang="en">http://bugs.php.net/bug.php?id=22048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040</vuln:reference>
    </vuln:references>
    <vuln:summary>The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1303">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1303</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10346" name="oval:org.mitre.oval:def:10346"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.php.net/bug.php?id=24150" xml:lang="en">http://bugs.php.net/bug.php?id=24150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1304">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_b"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_b001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_b002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_b003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_br"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_br001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6_br003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6b003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br001"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6br003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5003r"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.5004"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6002"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:1.6003"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:2"/>
        <cpe-lang:fact-ref name="cpe:/a:early_impact:productcart:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:early_impact:productcart:1.1</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.2</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.3</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.4</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_b</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_b001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_b002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_b003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_br</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_br001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6_br003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6b003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br001</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6br003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5003r</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.5004</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6002</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:1.6003</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:2</vuln:product>
      <vuln:product>cpe:/a:early_impact:productcart:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1304</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:48.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/0081.html" xml:lang="en">20030705 [Vulnerability] : ProductCart database file can be downloaded remotely</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf" xml:lang="en">http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/438189/100/200/threaded" xml:lang="en">20060622 productcart soltan_defacer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8112" xml:lang="en">8112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/9816" xml:lang="en">shopping-cart-database-access(9816)</vuln:reference>
    </vuln:references>
    <vuln:summary>EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1305">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0.2900"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1305</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:35.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-09-01T17:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2003/07/msg00068.html" xml:lang="en">20030707 Internet Explorer Crash</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1306">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:urlscan:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1306</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:35.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-10-16T11:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/sf/www-mobile/2003-q3/0021.html" xml:lang="en">[WWW-Mobile-Code] 20030706 can - IIS Version Disclosure</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1307">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32:beta:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.34:beta:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28:beta</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.28:beta:win32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32:beta:win32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.34:beta:win32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46::win32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1307</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:48.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.php.net/38915" xml:lang="en">http://bugs.php.net/38915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hackerdom.ru/~dimmo/phpexpl.c" xml:lang="en">http://hackerdom.ru/~dimmo/phpexpl.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348368" xml:lang="en">20031226 Hijacking Apache https by mod_php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/449234/100/0/threaded" xml:lang="en">20061019 PHP "exec", "system", "popen" problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/449298/100/0/threaded" xml:lang="en">20061020 Re: PHP "exec", "system", "popen" (+small POC)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9302" xml:lang="en">9302</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port.  NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1308">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fvwm:fvwm:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/a:fvwm:fvwm:2.5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fvwm:fvwm:2.4.17</vuln:product>
      <vuln:product>cpe:/a:fvwm:fvwm:2.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1308</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:35.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-11-20T13:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.fvwm.org/news/" xml:lang="en">http://www.fvwm.org/news/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9161" xml:lang="en">9161</vuln:reference>
    </vuln:references>
    <vuln:summary>CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1309">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm:3.7.202"/>
        <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm:3.7.211::plus"/>
        <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm:3.7.211::pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zonelabs:zonealarm:3.7.202</vuln:product>
      <vuln:product>cpe:/a:zonelabs:zonealarm:3.7.211::plus</vuln:product>
      <vuln:product>cpe:/a:zonelabs:zonealarm:3.7.211::pro</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1309</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:04.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0070.html" xml:lang="en">20030805 Local ZoneAlarm Firewall (probably all versions - tested on v3.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.zonelabs.com/bin/free/information/znalm/zaReleaseHistory.html" xml:lang="en">http://download.zonelabs.com/bin/free/information/znalm/zaReleaseHistory.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8342" xml:lang="en">8342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12824" xml:lang="en">device-driver-gain-privileges(12824)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").</vuln:summary>
  </entry>
  <entry id="CVE-2003-1310">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2002</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1310</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8329" xml:lang="en">8329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12824" xml:lang="en">device-driver-gain-privileges(12824)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").</vuln:summary>
  </entry>
  <entry id="CVE-2003-1311">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netegrity:siteminder"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1311</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:36.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-12-18T17:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://curl.haxx.se/mail/archive-2003-05/0172.html" xml:lang="en">[curl-users] 20030529 Re: https, redirection and authentication using POST</vuln:reference>
    </vuln:references>
    <vuln:summary>siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1312">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netegrity:siteminder"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1312</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:36.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-12-19T09:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://curl.haxx.se/mail/archive-2003-05/0172.html" xml:lang="en">[curl-users] 20030529 Re: https, redirection and authentication using POST</vuln:reference>
    </vuln:references>
    <vuln:summary>siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1313">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eternalmart:mailing_list_manager:1.32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eternalmart:mailing_list_manager:1.32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1313</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:36.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-12-28T16:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007884" xml:lang="en">1007884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/340244" xml:lang="en">20031004 EMML, EMGB : Include() hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8767" xml:lang="en">8767</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1314">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eternalmart:eternalmart_guestbook:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eternalmart:eternalmart_guestbook:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1314</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:01.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007885" xml:lang="en">1007885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/340244" xml:lang="en">20031004 EMML, EMGB : Include() hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21720" xml:lang="en">21720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8767" xml:lang="en">8767</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/2980" xml:lang="en">2980</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1315">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:neocrome:land_down_under:701"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neocrome:land_down_under:701</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1315</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008416" xml:lang="en">1008416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neocrome.net/index.php?m=single&amp;id=76" xml:lang="en">http://www.neocrome.net/index.php?m=single&amp;id=76</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neocrome.net/page.php?id=1250" xml:lang="en">http://www.neocrome.net/page.php?id=1250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9168" xml:lang="en">9168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13922" xml:lang="en">landdownunder-auth-sql-injection(13922)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1316">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:endonesia:endonesia:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1316</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007592" xml:lang="en">1007592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8507" xml:lang="en">8507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13042" xml:lang="en">endonesia-mod-path-disclosure(13042)</vuln:reference>
    </vuln:references>
    <vuln:summary>mod.php in eNdonesia 8.2 allows remote attackers to obtain sensitive information via a ' (quote) value in the lng parameter, which reveals the path in an error message.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1317">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:endonesia:endonesia:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1317</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007592" xml:lang="en">1007592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8506" xml:lang="en">8506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13041" xml:lang="en">endonesia-mod-xss(13041)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1318">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:twilight_utilities:twilight_webserver:1.3.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2003-1318</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:39:38.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=105820430209748&amp;w=2" xml:lang="en">20030713 TA-2003-07 Denial of Service Attack against Twilight WebServer v1.3.3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22090" xml:lang="en">22090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.tripbit.org/advisories/twilight_advisory.txt" xml:lang="en">http://www.tripbit.org/advisories/twilight_advisory.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1319">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smartftp:smartftp:1.0.973"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smartftp:smartftp:1.0.973</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1319</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0083.html" xml:lang="en">20030608 [SmartFTP] Two Buffer Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.nnov.ru/docs4679.html" xml:lang="en">http://security.nnov.ru/docs4679.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006956" xml:lang="en">1006956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7858" xml:lang="en">7858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7861" xml:lang="en">7861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12228" xml:lang="en">smartftp-pwd-directory-bo(12228)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12231" xml:lang="en">smartftp-long-list-bo(12231)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1320">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:sonicwall:firmware:6.4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:sonicwall:firmware:6.4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1320</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:37.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-28T11:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/287771" xml:lang="en">VU#287771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/AAMN-5L74VD" xml:lang="en">http://www.kb.cert.org/vuls/id/AAMN-5L74VD</vuln:reference>
    </vuln:references>
    <vuln:summary>SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1321">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:avant_force:avant_browser:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:avant_force:avant_browser:8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1321</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=106150462504484&amp;w=2" xml:lang="en">20030821 Buffer overflow in Avant Browser 8.02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8471" xml:lang="en">8471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12974" xml:lang="en">avantbrowser-http-bo(12974)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1322">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:atrium_software:mercur_mailserver:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:atrium_software:mercur_mailserver:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1322</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:37.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-04-10T11:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/12203.php" xml:lang="en">mercur-multiple-bo(12203)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/324136" xml:lang="en">20030606 Multiple Buffer Overflow Vulnerabilities Found in MERCUR Mail server v.4.2 (SP2) - IMAP protocol</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7842" xml:lang="en">7842</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1323">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:elm_development_group:elm:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:elm_development_group:elm:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1323</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:38.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-04-10T11:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz" xml:lang="en">http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz</vuln:reference>
    </vuln:references>
    <vuln:summary>Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1324">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:elmme-mailer:elm_me%2b:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:elmme-mailer:elm_me%2b:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1324</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:38.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-04-10T13:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz" xml:lang="en">http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1325">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:valve_software:half-life_cstrike_dedicated_server:1.1.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:valve_software:half-life_cstrike_dedicated_server:1.1.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1325</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:38.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.2</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-04-12T18:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/csdos.txt" xml:lang="en">http://aluigi.altervista.org/adv/csdos.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0304-exploits/hl-headnut.c" xml:lang="en">http://packetstormsecurity.org/0304-exploits/hl-headnut.c</vuln:reference>
    </vuln:references>
    <vuln:summary>The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1326">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1326</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:51.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A126" name="oval:org.mitre.oval:def:126"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A178" name="oval:org.mitre.oval:def:178"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A49" name="oval:org.mitre.oval:def:49"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-038.shtml" xml:lang="en">N-038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11258.php" xml:lang="en">ie-dialog-zone-bypass(11258)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6779" xml:lang="en">6779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-004" xml:lang="en">MS03-004</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1327">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1327</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-09/0348.html" xml:lang="en">20030922 Wu_ftpd all versions (not) vulnerability.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007775" xml:lang="en">1007775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8668" xml:lang="en">8668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2003&amp;m=slackware-security.365971" xml:lang="en">SSA:2003-259-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13269" xml:lang="en">wuftp-mailadmin-sockprintf-bo(13269)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1328">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1328</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:33:52.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A57" name="oval:org.mitre.oval:def:57"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0083.html" xml:lang="en">20030206 showHelp("file:") disables security in IE - Sandblad advisory #11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-038.shtml" xml:lang="en">N-038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11259.php" xml:lang="en">ie-showhelp-zone-bypass(11259)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/400577" xml:lang="en">VU#400577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6780" xml:lang="en">6780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-004" xml:lang="en">MS03-004</vuln:reference>
    </vuln:references>
    <vuln:summary>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1329</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:39.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-05-23T17:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/connect-dos.patch" xml:lang="en">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/connect-dos.patch</vuln:reference>
    </vuln:references>
    <vuln:summary>ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1330">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:clearswift_limited:mailsweeper:4.3.6_sp1::smtp"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift_limited:mailsweeper:4.3.6_sp1::smtp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1330</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7226" xml:lang="en">7226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11745" xml:lang="en">mailsweeper-onstrip-bypass-filter(11745)</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1331">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.9:gamma"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:mysql:4.0.9:gamma</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1331</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-07T12:42:03.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html" xml:lang="en">20030612 libmysqlclient 4.x and below mysql_real_connect() buffer overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.mysql.com/bug.php?id=564" xml:lang="en">http://bugs.mysql.com/bug.php?id=564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7887" xml:lang="en">7887</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12337" xml:lang="en">mysql-mysqlrealconnect-bo(12337)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1332">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1332</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-096.html" xml:lang="en">RHSA-2003:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/5TP0M2AAKS.html" xml:lang="en">http://www.securiteam.com/exploits/5TP0M2AAKS.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12749" xml:lang="en">samba-reply-nttrans-bo(12749)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1333">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:4.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:4.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5.0.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intersystems:cache_database:4.0.3</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:4.0.4</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:4.1.15</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:4.1.16</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5.0.3</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5.0.5</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5.0.12</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5.0.17</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5.0.19</vuln:product>
      <vuln:product>cpe:/a:intersystems:cache_database:5.0.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1333</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-08-21T14:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://groups.google.com/group/intersystems-public-cache/browse_thread/thread/8bdc0e496226edd1/60e9179edb4a4d43" xml:lang="en">http://groups.google.com/group/intersystems-public-cache/browse_thread/thread/8bdc0e496226edd1/60e9179edb4a4d43</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1334">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kai_blankenhorn_bitfolge:simple_and_nice_index_file:1.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kai_blankenhorn_bitfolge:simple_and_nice_index_file:1.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1334</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-08-23T11:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bitfolge.de/snif-en.html" xml:lang="en">http://www.bitfolge.de/snif-en.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1335">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kai_blankenhorn_bitfolge:simple_and_nice_index_file:1.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kai_blankenhorn_bitfolge:simple_and_nice_index_file:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1335</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-08-23T11:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bitfolge.de/snif-en.html" xml:lang="en">http://www.bitfolge.de/snif-en.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1336">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirc:mirc:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirc:mirc:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1336</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0060.html" xml:lang="en">20031015 mIRC Buffer Overflow in irc protocol handler</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6M00B0U8KE.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6M00B0U8KE.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8819" xml:lang="en">8819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13405" xml:lang="en">mirc-ircprotocol-execute-code(13405)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1337">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aprelium_technologies:abyss_web_server:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aprelium_technologies:abyss_web_server:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1337</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0235.html" xml:lang="en">20030629 Aprelium Abyss webserver X1 arbitrary code execution and header injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8062" xml:lang="en">8062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12466" xml:lang="en">abyss-http-get-bo(12466)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1338">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aprelium_technologies:abyss_web_server:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aprelium_technologies:abyss_web_server:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1338</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-24T17:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-06/0235.html" xml:lang="en">20030629 Aprelium Abyss webserver X1 arbitrary code execution and header injection</vuln:reference>
    </vuln:references>
    <vuln:summary>CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1339">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ezmeeting:ezmeeting:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ezmeeting:ezmeeting:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ezmeeting:ezmeeting:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ezmeeting:ezmeeting:3.3</vuln:product>
      <vuln:product>cpe:/a:ezmeeting:ezmeeting:3.4</vuln:product>
      <vuln:product>cpe:/a:ezmeeting:ezmeeting:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1339</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:19.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=107090390002654&amp;w=2" xml:lang="en">20031207 eZ Multiple Packages Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://seclists.org/bugtraq/2003/Dec/0195.html" xml:lang="en">20031211 eZ and eZphotoshare fixes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008412" xml:lang="en">1008412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.governmentsecurity.org/archive/t5390.html" xml:lang="en">http://www.governmentsecurity.org/archive/t5390.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/133" xml:lang="en">133</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1340">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpnuke:php-nuke:5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpnuke:php-nuke:6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpnuke:php-nuke:5.6</vuln:product>
      <vuln:product>cpe:/a:phpnuke:php-nuke:6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1340</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:48.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3185" xml:lang="en">3185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/323425" xml:lang="en">20030530 Php-Nuke:users and admins password hashes vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/480866/100/0/threaded" xml:lang="en">20070927 Re: [waraxe-2007-SA#056] - Another Sql Injection in NukeSentinel 2.5.11</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1341">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.0::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.0::corporate_for_windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.1.1::corporate_for_windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.5::corporate_for_windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.11::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.11::corporate_for_windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.13::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.13::corporate_for_windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.54::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:virus_buster:3.52::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:virus_buster:3.53::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:virus_buster:3.54::corporate"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:officescan:3.0::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.0::corporate_for_windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.1.1::corporate_for_windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.5::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.5::corporate_for_windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.11::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.11::corporate_for_windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.13::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.13::corporate_for_windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.54::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:virus_buster:3.52::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:virus_buster:3.53::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:virus_buster:3.54::corporate</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1341</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:05.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html" xml:lang="en">20030114 Assorted Trend Vulns Rev 2.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353" xml:lang="en">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6616" xml:lang="en">6616</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11059" xml:lang="en">officescan-cgichkmasterpwd-auth-bypass(11059)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1342">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:trend_micro:virus_control_system:1.8"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:virus_control_system:1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1342</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html" xml:lang="en">20030114 Assorted Trend Vulns Rev 2.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html" xml:lang="en">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6617" xml:lang="en">6617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11060" xml:lang="en">trend-vcs-activesupport-dos(11060)</vuln:reference>
    </vuln:references>
    <vuln:summary>Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1343">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:3.8::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:6.0::microsoft_exchange"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:scanmail:3.8::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:6.0::microsoft_exchange</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1343</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html" xml:lang="en">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352" xml:lang="en">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6619" xml:lang="en">6619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11061" xml:lang="en">scanmail-smgsmxcfg30-password-bypass(11061)</vuln:reference>
    </vuln:references>
    <vuln:summary>Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".</vuln:summary>
  </entry>
  <entry id="CVE-2003-1344">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:virus_control_system"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:virus_control_system</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1344</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html" xml:lang="en">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6618" xml:lang="en">6618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11063" xml:lang="en">trend-vcs-weak-encryption(11063)</vuln:reference>
    </vuln:references>
    <vuln:summary>Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1345">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:follett_software:webcollection_plus:5.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:follett_software:webcollection_plus:5.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1345</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104261317218210&amp;w=2" xml:lang="en">20030114 Vulnerability in WebCollection Plus (TM)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6574" xml:lang="en">6574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11064" xml:lang="en">webcollection-plus-directory-traversal(11064)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1346">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:d-link:dwl-900ap%2b:2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:d-link:dwl-900ap%2b:2.3"/>
        <cpe-lang:fact-ref name="cpe:/h:d-link:dwl-900ap%2b:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:d-link:dwl-900ap%2b:2.2</vuln:product>
      <vuln:product>cpe:/h:d-link:dwl-900ap%2b:2.3</vuln:product>
      <vuln:product>cpe:/h:d-link:dwl-900ap%2b:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1346</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104267037431451&amp;w=2" xml:lang="en">20030114 D-Link DWL-900AP+ Security Hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104311601319909&amp;w=2" xml:lang="en">20030116 Re: D-Link DWL-900AP+ Security Hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6609" xml:lang="en">6609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005926" xml:lang="en">1005926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11074" xml:lang="en">dlink-airplus-restore-default(11074)</vuln:reference>
    </vuln:references>
    <vuln:summary>D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware using AirPlus Access Point Manager.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1347">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:geeklog:geeklog:1.3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geeklog:geeklog:1.3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1347</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3226" xml:lang="en">3226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.geeklog.net/filemgmt/visit.php?lid=101" xml:lang="en">http://www.geeklog.net/filemgmt/visit.php?lid=101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/306770" xml:lang="en">20030114 Multiple XSS in Geeklog 1.3.7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6601" xml:lang="en">6601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6602" xml:lang="en">6602</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6603" xml:lang="en">6603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6604" xml:lang="en">6604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11075" xml:lang="en">geeklog-php-scripts-xss(11075)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1348">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ftls:guestbook:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ftls:guestbook:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1348</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3227" xml:lang="en">3227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308312" xml:lang="en">20030125 ftls.org  Guestbook 1.1 Script Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6686" xml:lang="en">6686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11155" xml:lang="en">guestbook-multiple-field-xss(11155)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1349">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:thomas_krebs:niteserver_ftpd:1.83"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thomas_krebs:niteserver_ftpd:1.83</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1349</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0022.html" xml:lang="en">20030115 Directory traversal vulnerabilities found in NITE ftp-server version 1.83</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6648" xml:lang="en">6648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005923" xml:lang="en">1005923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11062" xml:lang="en">niteserver-dotdot-directory-traversal(11062)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1350">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:list_site_pro:list_site_pro:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:list_site_pro:list_site_pro:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1350</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3230" xml:lang="en">3230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308300" xml:lang="en">20030124 List Site Pro v2 user account Hijacking vulnerablity</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6685" xml:lang="en">6685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11156" xml:lang="en">listsitepro-account-hijacking(11156)</vuln:reference>
    </vuln:references>
    <vuln:summary>List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1351">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:greg_billock:edittag:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:greg_billock:edittag:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1351</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3231" xml:lang="en">3231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308162" xml:lang="en">20030124 Vulnerability in edittag.pl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6675" xml:lang="en">6675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11159" xml:lang="en">edittag-dotdot-directory-traversal(11159)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1352">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gabber:gabber:0.8.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gabber:gabber:0.8.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1352</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:06.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0179.html" xml:lang="en">20030115 Gabber 0.8.7 leaks presence information without user authorization</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6624" xml:lang="en">6624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11115" xml:lang="en">gabber-information-leak(11115)</vuln:reference>
    </vuln:references>
    <vuln:summary>Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1353">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lanifex:outreach_project_tool:0.946b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lanifex:outreach_project_tool:0.946b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1353</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0119.html" xml:lang="en">20030116 Outreach Project Tool</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6631" xml:lang="en">6631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11096" xml:lang="en">opt-news-post-xss(11096)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1354">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gamespy3d:gamespy_3d:2.62"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gamespy3d:gamespy_3d:2.62</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1354</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://seclists.org/lists/bugtraq/2003/Jan/0178.html" xml:lang="en">20030122 PivX Multi-Vendor Game Server dDoS Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pivx.com/kristovich/adv/mk001/" xml:lang="en">http://www.pivx.com/kristovich/adv/mk001/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/5EP0O0K8UO.html" xml:lang="en">http://www.securiteam.com/securitynews/5EP0O0K8UO.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6636" xml:lang="en">6636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11084" xml:lang="en">battlefield-udp-query-dos(11084)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1355">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:electronic_arts:battlefield_1942:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:electronic_arts:battlefield_1942:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:electronic_arts:battlefield_1942:1.2</vuln:product>
      <vuln:product>cpe:/a:electronic_arts:battlefield_1942:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1355</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0342.html" xml:lang="en">20030226 [VSA0307] Battlefield 1942 remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6967" xml:lang="en">6967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11426" xml:lang="en">battlefield-remoteconsole-username-dos(11426)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1356">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1356</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:19.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5758" name="oval:org.mitre.oval:def:5758"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q1/0009.html" xml:lang="en">SSRT3454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6640" xml:lang="en">6640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11107" xml:lang="en">hpux-sort-file-handling(11107)</vuln:reference>
    </vuln:references>
    <vuln:summary>The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1357">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:replicom:proxyview"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:replicom:proxyview</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1357</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3228" xml:lang="en">3228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308733" xml:lang="en">20030128 ProxyView default undocumented password</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6708" xml:lang="en">6708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11185" xml:lang="en">proxyview-administrator-default-password(11185)</vuln:reference>
    </vuln:references>
    <vuln:summary>ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1358">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.0.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1358</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3236" xml:lang="en">3236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/4960" xml:lang="en">HPSBUX0302-240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/324381" xml:lang="en">20030710 [LSD] HP-UX security vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6837" xml:lang="en">6837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11312" xml:lang="en">hp-rsf3000-daemon-access(11312)</vuln:reference>
    </vuln:references>
    <vuln:summary>rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1359">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:avaya:predictive_dialer_system:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:avaya:predictive_dialer_system:11"/>
        <cpe-lang:fact-ref name="cpe:/a:avaya:predictive_dialer_system:12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:avaya:predictive_dialer_system:9.0</vuln:product>
      <vuln:product>cpe:/a:avaya:predictive_dialer_system:11</vuln:product>
      <vuln:product>cpe:/a:avaya:predictive_dialer_system:12</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.0.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1359</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:19.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5587" name="oval:org.mitre.oval:def:5587"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3236" xml:lang="en">3236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/4959" xml:lang="en">HPSBUX0302-241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/324381" xml:lang="en">20030610 [LSD] HP-UX security vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6836" xml:lang="en">6836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11313" xml:lang="en">hp-stmkfont-bo(11313)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1360">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1360</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3236" xml:lang="en">3236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/4957" xml:lang="en">HPSBUX0302-243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/324381" xml:lang="en">20030610 [LSD] HP-UX security vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6834" xml:lang="en">6834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11314" xml:lang="en">hp-landiag-lanadmin-bo(11314)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1361">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:tivoli_storage_manager:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:tivoli_storage_manager:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:veritas:bare_metal_restore"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:veritas:bare_metal_restore</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1361</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html" xml:lang="en">20030225 VERITAS Software Technical Advisory (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://seer.support.veritas.com/docs/252933.htm" xml:lang="en">http://seer.support.veritas.com/docs/252933.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://seer.support.veritas.com/docs/254442.htm" xml:lang="en">http://seer.support.veritas.com/docs/254442.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6928" xml:lang="en">6928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11418" xml:lang="en">veritas-bmr-root-access(11418)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1362">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:bastille:b.02.00.05::hp-ux"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:bastille:b.02.00.05::hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1362</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q1/0033.html" xml:lang="en">HPSBUX0302-245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6878" xml:lang="en">6878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11366" xml:lang="en">hp-bastille-info-disclosure(11366)</vuln:reference>
    </vuln:references>
    <vuln:summary>Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1363">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aprelium_technologies:abyss_web_server:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aprelium_technologies:abyss_web_server:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1363</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:44.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-11-29T12:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html" xml:lang="en">20030212 Abyss WebServer Brute Force Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11310.php" xml:lang="en">abyss-web-admin-bruteforce(11310)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6842" xml:lang="en">6842</vuln:reference>
    </vuln:references>
    <vuln:summary>The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1364">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aprelium_technologies:abyss_web_server:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aprelium_technologies:abyss_web_server:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1364</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-04/0095.html" xml:lang="en">20030405 Abyss X1 1.1.2 remote crash</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7287" xml:lang="en">7287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11718" xml:lang="en">abyss-http-get-dos(11718)</vuln:reference>
    </vuln:references>
    <vuln:summary>Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1365">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:perl:cgi_lite:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:perl:cgi_lite:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1365</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0065.html" xml:lang="en">20030211 Security bug in CGI::Lite::escape_dangerous_chars() function</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://search.cpan.org/~smylers/CGI-Lite-2.02/Lite.pm" xml:lang="en">http://search.cpan.org/~smylers/CGI-Lite-2.02/Lite.pm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3237" xml:lang="en">3237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://use.perl.org/~cbrooks/journal/10542" xml:lang="en">http://use.perl.org/~cbrooks/journal/10542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311414" xml:lang="en">20030211 Security bug in CGI::Lite::escape_dangerous_chars() function</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6833" xml:lang="en">6833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11308" xml:lang="en">cgilite-shell-command-execution(11308)</vuln:reference>
    </vuln:references>
    <vuln:summary>The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1366">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1366</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3238" xml:lang="en">3238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309962" xml:lang="en">20030203 ASA-0001: OpenBSD chpass/chfn/chsh file content leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6748" xml:lang="en">6748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006035" xml:lang="en">1006035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11233" xml:lang="en">openbsd-chpass-information-disclosure(11233)</vuln:reference>
    </vuln:references>
    <vuln:summary>chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1367">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:1.94.4"/>
        <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:1.94.5"/>
        <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:great_circle_associates:majordomo:1.94.4</vuln:product>
      <vuln:product>cpe:/a:great_circle_associates:majordomo:1.94.5</vuln:product>
      <vuln:product>cpe:/a:great_circle_associates:majordomo:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1367</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3235" xml:lang="en">3235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310113" xml:lang="en">20030204 Majordomo info leakage, all versions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6761" xml:lang="en">6761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11243" xml:lang="en">majordomo-whichaccess-email-disclosure(11243)</vuln:reference>
    </vuln:references>
    <vuln:summary>The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1368">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:electrasoft:ftp_client:9.49.01::32bit"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:electrasoft:ftp_client:9.49.01::32bit</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1368</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0054.html" xml:lang="en">20030204 Banner Buffer Overflows found in Multible FTP Clients</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6764" xml:lang="en">6764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11234" xml:lang="en">32bit-ftp-banner-bo(11234)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1369">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:save_it_software_pty:bytecatcherftp:1.04b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:save_it_software_pty:bytecatcherftp:1.04b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1369</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0054.html" xml:lang="en">20030204 Banner Buffer Overflows found in Multible FTP Clients</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6762" xml:lang="en">6762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11235" xml:lang="en">bytecatcher-ftp-banner-bo(11235)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1370">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1370</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:07.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0330.html" xml:lang="en">20030127 [SCSA-003] Multiple Cross Site Scripting &amp; Script Injection Vulnerabilities in Nuked-Klan</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6697" xml:lang="en">6697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6699" xml:lang="en">6699</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6700" xml:lang="en">6700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11176" xml:lang="en">nuked-klan-index-xss(11176)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1371">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1371</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html" xml:lang="en">20030221 [SCSA-006] XSS &amp; Function Execution Vulnerabilities in Nuked-Klan</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6917" xml:lang="en">6917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11424" xml:lang="en">nukedklan-information-disclosure(11424)</vuln:reference>
    </vuln:references>
    <vuln:summary>Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1372">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
          <cpe-lang:fact-ref name="cpe:/o:unix:unix:any_version"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:myphpnuke:myphpnuke:1.8.8"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myphpnuke:myphpnuke:1.8.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1372</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0231.html" xml:lang="en">20030219 myphpnuke xss</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6892" xml:lang="en">6892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11376" xml:lang="en">phpbb-index-sql-injection(11376)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1373">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:1.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.0</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.1</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.2</vuln:product>
      <vuln:product>cpe:/a:phpbb_group:phpbb:1.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1373</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0245.html" xml:lang="en">20030220 phpBB Security Bugs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6889" xml:lang="en">6889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11407" xml:lang="en">phpbb-auth-read-files(11407)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1374">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1374</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0156.html" xml:lang="en">20030213 HPUX disable buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6845" xml:lang="en">6845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11316" xml:lang="en">hp-lp-disable-bo(11316)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in disable of HP-UX 11.0 may allow local users to execute arbitrary code via a long argument to the (1) -r or (2)-c options.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1375">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1375</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:19.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5439" name="oval:org.mitre.oval:def:5439"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3264" xml:lang="en">3264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5369" xml:lang="en">HPSBUX0305-258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310908" xml:lang="en">20030207 HPUX Wall Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6800" xml:lang="en">6800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11272" xml:lang="en">hp-wall-bo(11272)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1376">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:winzip:winzip:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:winzip:winzip:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1376</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3265" xml:lang="en">3265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311059" xml:lang="en">20030208 Yet another plaintext attack to ZIP encryption scheme.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6805" xml:lang="en">6805</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11296" xml:lang="en">winzip-pkzip-weak-encryption(11296)</vuln:reference>
    </vuln:references>
    <vuln:summary>WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1377">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sircd:sircd:0.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sircd:sircd:0.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sircd:sircd:0.4.0</vuln:product>
      <vuln:product>cpe:/a:sircd:sircd:0.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1377</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312924" xml:lang="en">20030223 sircd proof-of-concept / advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6924" xml:lang="en">6924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11409" xml:lang="en">sircd-reverse-dns-bo(11409)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the reverse DNS lookup of Smart IRC Daemon (SIRCD) 0.4.0 and 0.4.4 allows remote attackers to execute arbitrary code via a client with a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1378">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook_express:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1378</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312910" xml:lang="en">20030223 O UT LO OK  E  XPRE SS 6 .00 : broken</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312929" xml:lang="en">20030224 Re: O UT LO OK  E  XPRE SS 6 .00 : broken</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6923" xml:lang="en">6923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11411" xml:lang="en">outlook-codebase-execute-programs(11411)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1379">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:point_clark_networks:clarkconnect:1.2::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:point_clark_networks:clarkconnect:1.2::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1379</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313080" xml:lang="en">20030225 clarkconnect(d) information disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6934" xml:lang="en">6934</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11419" xml:lang="en">clarkconnect-clarkconnectd-info-disclosure(11419)</vuln:reference>
    </vuln:references>
    <vuln:summary>clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1380">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:bisonftp:bisonftp_server_4:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:bisonftp:bisonftp_server_4:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1380</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312032" xml:lang="en">20030217 [immune advisory] Mulitple vulnerabilities found in BisonFTP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6873" xml:lang="en">6873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11347" xml:lang="en">bisonftp-ls-view-files(11347)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1381">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:amxmod.net:amx_mod:0.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:amxmod.net:amx_mod:0.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1381</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3258" xml:lang="en">3258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313273" xml:lang="en">20030226 [VSA0308] Half-Life AMX-Mod remote (root) hole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6968" xml:lang="en">6968</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11427" xml:lang="en">amx-amxsay-format-string(11427)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1382">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:instantservers_inc.:ismail:1.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:instantservers_inc.:ismail:1.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1382</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3254" xml:lang="en">3254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313363" xml:lang="en">20030227 ISMAIL (All Versions) Remote Buffer Overrun</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6972" xml:lang="en">6972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11432" xml:lang="en">ismail-smtp-domain-bo(11432)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ISMail 1.4.3 and earlier allow remote attackers to execute arbitrary code via long domain names in (1) MAIL FROM or (2) RCPT TO fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1383">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:logicworks:web_erp:0.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:logicworks:web_erp:0.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1383</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3257" xml:lang="en">3257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313575" xml:lang="en">20030301 web-erp 0.1.4 database access vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6996" xml:lang="en">6996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11443" xml:lang="en">weberp-logicworks-ini-access(11443)</vuln:reference>
    </vuln:references>
    <vuln:summary>WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1384">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:py_software:py-livredor:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:py_software:py-livredor:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1384</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0102.html" xml:lang="en">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://cert.uni-stuttgart.de/archive/bugtraq/2003/03/msg00024.html" xml:lang="en">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004015.html" xml:lang="en">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6997" xml:lang="en">6997</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11448" xml:lang="en">pylivredor-guestbook-xss(11448)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1385">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_power_board:1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:invision_power_services:invision_power_board:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1385</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0099.html" xml:lang="en">20030227 Invision Power Board (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6976" xml:lang="en">6976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11435" xml:lang="en">invision-ipchat-file-include(11435)</vuln:reference>
    </vuln:references>
    <vuln:summary>ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1386">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:axis:2400_video_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2400_video_server:2.20"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2400_video_server:2.31"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2400_video_server:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2400_video_server:2.33"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2401_video_server:2.20"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2401_video_server:2.31"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2401_video_server:2.32"/>
        <cpe-lang:fact-ref name="cpe:/h:axis:2401_video_server:2.33"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:axis:2400_video_server:2.0</vuln:product>
      <vuln:product>cpe:/h:axis:2400_video_server:2.20</vuln:product>
      <vuln:product>cpe:/h:axis:2400_video_server:2.31</vuln:product>
      <vuln:product>cpe:/h:axis:2400_video_server:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2400_video_server:2.33</vuln:product>
      <vuln:product>cpe:/h:axis:2401_video_server:2.20</vuln:product>
      <vuln:product>cpe:/h:axis:2401_video_server:2.31</vuln:product>
      <vuln:product>cpe:/h:axis:2401_video_server:2.32</vuln:product>
      <vuln:product>cpe:/h:axis:2401_video_server:2.33</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1386</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0377.html" xml:lang="en">20030228 axis2400 webcams</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0370.html" xml:lang="en">20030325 Axis Video and Camera Servers - System log access and file access/overwrite via HTTP/CGI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6980" xml:lang="en">6980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.websec.org/adv/axis2400.txt.html" xml:lang="en">http://www.websec.org/adv/axis2400.txt.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11440" xml:lang="en">axis-messages-unauth-access(11440)</vuln:reference>
    </vuln:references>
    <vuln:summary>AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1387">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.5::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.6::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.5::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.6::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1387</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3253" xml:lang="en">3253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311194" xml:lang="en">20030209 Opera Username Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315794" xml:lang="en">20030320 Opara 6.06 Released, Security-Hole Left</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6811" xml:lang="en">6811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11281" xml:lang="en">opera-username-url-bo(11281)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1388">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
          <cpe-lang:fact-ref name="cpe:/o:unix:unix:any_version"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:opera_software:opera:7.02_build_2668"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera:7.02_build_2668</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1388</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:08.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-04/0116.html" xml:lang="en">20030407 Unchecked Buffer in Opera 7.02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11740" xml:lang="en">opera-long-url-bo(11740)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1389">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.0</vuln:product>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1389</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311176" xml:lang="en">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6815" xml:lang="en">6815</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11294" xml:lang="en">cryptobuddy-truncate-weak-security(11294)</vuln:reference>
    </vuln:references>
    <vuln:summary>RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1390">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.0</vuln:product>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1390</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311176" xml:lang="en">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11297" xml:lang="en">cryptobuddy-plaintext-password-bytes(11297)</vuln:reference>
    </vuln:references>
    <vuln:summary>RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1391">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.0</vuln:product>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1391</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311176" xml:lang="en">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6810" xml:lang="en">6810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11298" xml:lang="en">cryptobuddy-password-dictionary(11298)</vuln:reference>
    </vuln:references>
    <vuln:summary>RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1392">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:research_triangle_software:cryptobuddy:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.0</vuln:product>
      <vuln:product>cpe:/a:research_triangle_software:cryptobuddy:1.2</vuln:product>
      <vuln:product>cpe:/o:microsoft:all_windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1392</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311176" xml:lang="en">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6812" xml:lang="en">6812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11317" xml:lang="en">cryptobuddy-password-information-disclosure(11317)</vuln:reference>
    </vuln:references>
    <vuln:summary>CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1393">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gupta_technologies:sqlbase:8.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gupta_technologies:sqlbase:8.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1393</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3256" xml:lang="en">3256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311159" xml:lang="en">20030210 Buffer OverFlow in SQLBase 8.1.0 - NII Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/314379" xml:lang="en">20030308 NII Advisory - Buffer Overflow in SQLBase (Revised)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6808" xml:lang="en">6808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11269" xml:lang="en">sqlbase-execute-long-bo(11269)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Gupta SQLBase 8.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long EXECUTE command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1394">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:coffeecup_software:coffeecup_password_wizard:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coffeecup_software:coffeecup_password_wizard:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1394</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3259" xml:lang="en">3259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313580" xml:lang="en">20030228 Easy obtaining User+Pass+More on CoffeeCup Password Wizard All Versions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6995" xml:lang="en">6995</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11447" xml:lang="en">coffeecup-password-file-retrieval(11447)</vuln:reference>
    </vuln:references>
    <vuln:summary>CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1395">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kazaa:kazaa_media_desktop:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:kazaa:kazaa_media_desktop:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kazaa:kazaa_media_desktop:2.0</vuln:product>
      <vuln:product>cpe:/a:kazaa:kazaa_media_desktop:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1395</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3252" xml:lang="en">3252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309935" xml:lang="en">20030202 Denial of service against Kazaa Media Desktop v2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6747" xml:lang="en">6747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11228" xml:lang="en">kazaa-automated-ad-bo(11228)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1396">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.4::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.5::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.3::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.4::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.5::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.3::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1396</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-04/0346.html" xml:lang="en">20030427 [Opera 7/6] Long File Extension Heap Buffer Overrun Vulnerability in Download.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7450" xml:lang="en">7450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11894" xml:lang="en">opera-file-extension-bo(11894)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1397">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.5::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.5::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1397</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3255" xml:lang="en">3255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311214" xml:lang="en">20030210 Java-Applet crashes Opera 6.05 and 7.01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6814" xml:lang="en">6814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11280" xml:lang="en">opera-plugincontextshowdocument-bo(11280)</vuln:reference>
    </vuln:references>
    <vuln:summary>The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1398">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2f</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1398</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0131.html" xml:lang="en">20030211 Field Notice - IOS Accepts ICMP Redirects in Non-default Configuration Settings</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006075" xml:lang="en">1006075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6823" xml:lang="en">6823</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11306" xml:lang="en">cisco-ios-icmp-redirect(11306)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1399">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eject:eject:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:eject:eject:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:eject:eject:2.0.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eject:eject:2.0.10</vuln:product>
      <vuln:product>cpe:/a:eject:eject:2.0.11</vuln:product>
      <vuln:product>cpe:/a:eject:eject:2.0.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1399</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0278.html" xml:lang="en">20030222 eject 2.0.10 vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6914" xml:lang="en">6914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11380" xml:lang="en">linux-eject-information-disclosure(11380)</vuln:reference>
    </vuln:references>
    <vuln:summary>eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1400">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.0</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.0.1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.2</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.2a</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.3.1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.4</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.5</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.6</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1400</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309959" xml:lang="en">20030203 PHP-Nuke Avatar Code injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310115" xml:lang="en">20030204 Re: PHP-Nuke Avatar Code injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6750" xml:lang="en">6750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11229" xml:lang="en">phpnuke-avatar-code-execution(11229)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1401">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php_board:php_board:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_board:php_board:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1401</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0069.html" xml:lang="en">20030215 php-Board (php)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6862" xml:lang="en">6862</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11338" xml:lang="en">phpboard-login-plaintext-passwords(11338)</vuln:reference>
    </vuln:references>
    <vuln:summary>login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1402">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kietu:kietu:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:kietu:kietu:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kietu:kietu:2.0</vuln:product>
      <vuln:product>cpe:/a:kietu:kietu:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1402</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0071.html" xml:lang="en">20030215 Kietu ( PHP )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6863" xml:lang="en">6863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11341" xml:lang="en">kietu-hit-file-include(11341)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1403">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dotbr:botbr:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dotbr:botbr:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1403</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html" xml:lang="en">20030215 DotBr (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6864" xml:lang="en">6864</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11353" xml:lang="en">dotbr-foo-info-disclosure(11353)</vuln:reference>
    </vuln:references>
    <vuln:summary>foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1404">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dotbr:botbr:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dotbr:botbr:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1404</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:09.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html" xml:lang="en">20030215 DotBr (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6865" xml:lang="en">6865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11354" xml:lang="en">dotbr-config-info-disclosure(11354)</vuln:reference>
    </vuln:references>
    <vuln:summary>DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1405">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dotbr:botbr:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dotbr:botbr:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1405</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html" xml:lang="en">20030215 DotBr (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6866" xml:lang="en">6866</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6867" xml:lang="en">6867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11355" xml:lang="en">dotbr-exec-execute-commands(11355)</vuln:reference>
    </vuln:references>
    <vuln:summary>DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1406">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adalis_infomatique:d_forum:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adalis_infomatique:d_forum:1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:adalis_infomatique:d_forum:1.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adalis_infomatique:d_forum:1.0</vuln:product>
      <vuln:product>cpe:/a:adalis_infomatique:d_forum:1.10</vuln:product>
      <vuln:product>cpe:/a:adalis_infomatique:d_forum:1.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1406</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0072.html" xml:lang="en">20030216 D-Forum (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6879" xml:lang="en">6879</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11342" xml:lang="en">dform-header-file-include(11342)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1407">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1407</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3251" xml:lang="en">3251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311359" xml:lang="en">20030211 SECURITY.NNOV: Windows NT 4.0/2000 cmd.exe long path buffer overflow/DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6829" xml:lang="en">6829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11329" xml:lang="en">win-cmd-cd-bo(11329)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1408">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lotus:domino_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:lotus:domino_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lotus:domino_server:5.0</vuln:product>
      <vuln:product>cpe:/a:lotus:domino_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1408</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311660" xml:lang="en">20030212 Lotus Domino DOT Bug Allows for Source Code Viewing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311806" xml:lang="en">20030213 Re: Lotus Domino DOT Bug Allows for Source Code Viewing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6841" xml:lang="en">6841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11311" xml:lang="en">lotus-domino-dot-file-download(11311)</vuln:reference>
    </vuln:references>
    <vuln:summary>Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1409">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ej3:topo:1.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ej3:topo:1.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1409</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0049.html" xml:lang="en">20030204 TOPo 1.43 and prior - Path Disclosure (in.php, out.php)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6768" xml:lang="en">6768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11248" xml:lang="en">topo-path-disclosure(11248)</vuln:reference>
    </vuln:references>
    <vuln:summary>TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1410">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isoca:cedric_email_reader:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isoca:cedric_email_reader:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isoca:cedric_email_reader:0.2</vuln:product>
      <vuln:product>cpe:/a:isoca:cedric_email_reader:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1410</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.310-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311173" xml:lang="en">20030209 Cedric Email Reader (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6818" xml:lang="en">6818</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11278" xml:lang="en">cedric-email-file-include(11278)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1411">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isoca:cedric_email_reader:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isoca:cedric_email_reader:0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1411</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311173" xml:lang="en">20030209 Cedric Email Reader (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6820" xml:lang="en">6820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11278" xml:lang="en">cedric-email-file-include(11278)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1412">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gonicus:gonicus_system_administration:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gonicus:gonicus_system_administration:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1412</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:49.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003932.html" xml:lang="en">20030223 GOnicus System Administrator php injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313282/30/25760/threaded" xml:lang="en">20030224 GOnicus System Administrator php injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6922" xml:lang="en">6922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006162" xml:lang="en">1006162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11408" xml:lang="en">gosa-plugin-file-include(11408)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1413">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1413</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3260" xml:lang="en">3260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313517" xml:lang="en">20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6992" xml:lang="en">6992</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11445" xml:lang="en">darwin-dotdot-file-existence(11445)</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1414">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1414</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3260" xml:lang="en">3260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313517" xml:lang="en">20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6990" xml:lang="en">6990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11446" xml:lang="en">darwin-dotdotdot-directory-traversal(11446)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1415">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:visual_mining:netcharts_xbrl_server:4.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:visual_mining:netcharts_xbrl_server:4.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1415</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3261" xml:lang="en">3261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312187" xml:lang="en">20030218 [SecurityOffice] Netcharts XBRL Server v4.0.0 Information Leakage Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6877" xml:lang="en">6877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11345" xml:lang="en">netcharts-chunked-encoding-bo(11345)</vuln:reference>
    </vuln:references>
    <vuln:summary>NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1416">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:bisonftp:bisonftp_server_4:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:bisonftp:bisonftp_server_4:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1416</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312032" xml:lang="en">20030217 [immune advisory] Mulitple vulnerabilities found in BisonFTP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6869" xml:lang="en">6869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11346" xml:lang="en">bisonftp-ls-cwd-dos(11346)</vuln:reference>
    </vuln:references>
    <vuln:summary>BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1417">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ncipher:support_software:6.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncipher:support_software:6.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1417</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104619088801750&amp;w=2" xml:lang="en">20030225 nCipher Advisory #7: Unexpected copies of imported software keys</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6927" xml:lang="en">6927</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11422" xml:lang="en">ncipher-duplicate-keys(11422)</vuln:reference>
    </vuln:references>
    <vuln:summary>nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1418">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1418</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-19T21:29:00.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata32.html" xml:lang="en">[3.2] 008: SECURITY FIX: February 25, 2003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" xml:lang="en">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6939" xml:lang="en">6939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6943" xml:lang="en">6943</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11438" xml:lang="en">apache-mime-information-disclosure(11438)</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1419">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:navigator:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1419</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0338.html" xml:lang="en">20030225 Re: Netscape 6/7 crashes by a simple stylesheet...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6959" xml:lang="en">6959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11444" xml:lang="en">netscape-javascript-reformatdate-dos(11444)</vuln:reference>
    </vuln:references>
    <vuln:summary>Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1420">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.4::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.5::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.10::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.4::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.5::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:6.10::linux</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.1::win32</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera_web_browser:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1420</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313216" xml:lang="en">20030226 Secunia Research: Opera browser Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6962" xml:lang="en">6962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11423" xml:lang="en">opera-automatic-redirection-xss(11423)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1421">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:suckbot:suckbot:0.006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:suckbot:suckbot:0.006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1421</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6854" xml:lang="en">6854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11340" xml:lang="en">suckbot-modmysqllogger-dos(11340)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1422">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gentoo:syslinux:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gentoo:syslinux:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1422</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://syslinux.zytor.com/history.php" xml:lang="en">http://syslinux.zytor.com/history.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6876" xml:lang="en">6876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11351" xml:lang="en">syslinux-gain-privileges(11351)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1423">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
          <cpe-lang:fact-ref name="cpe:/o:unix:unix:any_version"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:petitforum:petitforum"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:petitforum:petitforum</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1423</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006117" xml:lang="en">1006117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11358" xml:lang="en">petitforum-liste-info-disclosure(11358)</vuln:reference>
    </vuln:references>
    <vuln:summary>Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1424">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:petitforum:petitforum"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:petitforum:petitforum</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1424</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:10.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006117" xml:lang="en">1006117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11359" xml:lang="en">petitforum-message-auth-bypass(11359)</vuln:reference>
    </vuln:references>
    <vuln:summary>message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1425">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cpanel:cpanel:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1425</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html" xml:lang="en">20030218 Cpanel 5 and below remote command execution and local root vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6882" xml:lang="en">6882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11356" xml:lang="en">cpanel-guestbook-command-execution(11356)</vuln:reference>
    </vuln:references>
    <vuln:summary>guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1426">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cpanel:cpanel:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cpanel:cpanel:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1426</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html" xml:lang="en">20030218 Cpanel 5 and below remote command execution and local root vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6885" xml:lang="en">6885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11357" xml:lang="en">cpanel-scriptfilename-gain-privileges(11357)</vuln:reference>
    </vuln:references>
    <vuln:summary>Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1427">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:netgear:fm114p:1.4_beta_release_17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:netgear:fm114p:1.4_beta_release_17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1427</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311160" xml:lang="en">20030209 Bug in Netgear FM114P Wireless Router firmware</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6807" xml:lang="en">6807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11279" xml:lang="en">netgear-fm114p-directory-traversal(11279)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1428">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:bharat_mediratta:gallery:1.3.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bharat_mediratta:gallery:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1428</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.8</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311161" xml:lang="en">20030210 Gallery 1.3.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6809" xml:lang="en">6809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11284" xml:lang="en">gallery-album-insecure-directory(11284)</vuln:reference>
    </vuln:references>
    <vuln:summary>Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1429">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:proxomitron:proxomitron_naoko:4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:proxomitron:proxomitron_naoko:4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1429</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0088.html" xml:lang="en">20030219 [SCSA-005] Proxomitron Naoko Long Path Buffer Overflow/DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11364" xml:lang="en">proxomitron-parameter-length-bo(11364)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1430">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:226f"/>
          <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:433"/>
          <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:436"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epic_games:unreal_engine:226f</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:433</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:436</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1430</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" xml:lang="en">20030205 Unreal engine: results of my research</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" xml:lang="en">20030211 Re: Epic Games threatens to sue security researchers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6775" xml:lang="en">6775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11299" xml:lang="en">ut-file-directory-traversal(11299)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1431">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:226f"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:433"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:436"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epic_games:unreal_engine:226f</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:433</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:436</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1431</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" xml:lang="en">20030205 Unreal engine: results of my research</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" xml:lang="en">20030211 Re: Epic Games threatens to sue security researchers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6774" xml:lang="en">6774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11301" xml:lang="en">ut-url-memory-corruption(11301)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1432">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:226f"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:433"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:436"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_tournament_2003:2199_linux"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_tournament_2003:2199_win32"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_tournament_2003:demo_version_2206_linux"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_tournament_2003:demo_version_2206_win32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epic_games:unreal_engine:226f</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:433</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:436</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_tournament_2003:2199_linux</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_tournament_2003:2199_win32</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_tournament_2003:demo_version_2206_linux</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_tournament_2003:demo_version_2206_win32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1432</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" xml:lang="en">20030205 Unreal engine: results of my research</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" xml:lang="en">20030211 Re: Epic Games threatens to sue security researchers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0142.html" xml:lang="en">20030513 UT2003 client passive DoS exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6770" xml:lang="en">6770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6772" xml:lang="en">6772</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11302" xml:lang="en">ut-packet-dos(11302)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11305" xml:lang="en">ut-negative-memory-corruption(11305)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12012" xml:lang="en">ut-negative-udp-dos(12012)</vuln:reference>
    </vuln:references>
    <vuln:summary>Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1433">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:226f"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:433"/>
        <cpe-lang:fact-ref name="cpe:/a:epic_games:unreal_engine:436"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epic_games:unreal_engine:226f</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:433</vuln:product>
      <vuln:product>cpe:/a:epic_games:unreal_engine:436</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1433</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" xml:lang="en">20030205 Unreal engine: results of my research</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" xml:lang="en">20030211 Re: Epic Games threatens to sue security researchers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6771" xml:lang="en">6771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11304" xml:lang="en">ut-join-request-dos(11304)</vuln:reference>
    </vuln:references>
    <vuln:summary>Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1434">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pete_werner:login_ldap:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pete_werner:login_ldap:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pete_werner:login_ldap:3.1</vuln:product>
      <vuln:product>cpe:/a:pete_werner:login_ldap:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1434</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0244.html" xml:lang="en">20030220 login_ldap security announcement</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6903" xml:lang="en">6903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11374" xml:lang="en">loginldap-password-bypass(11374)</vuln:reference>
    </vuln:references>
    <vuln:summary>login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1435">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:5.6</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1435</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0246.html" xml:lang="en">20030220 PHPNuke SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6887" xml:lang="en">6887</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11375" xml:lang="en">phpnuke-search-sql-injection(11375)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1436">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:crossnuke:nukebrowser:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:crossnuke:nukebrowser:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:crossnuke:nukebrowser:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:crossnuke:nukebrowser:2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:crossnuke:nukebrowser:2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:crossnuke:nukebrowser:2.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:crossnuke:nukebrowser:2.1</vuln:product>
      <vuln:product>cpe:/a:crossnuke:nukebrowser:2.3</vuln:product>
      <vuln:product>cpe:/a:crossnuke:nukebrowser:2.5</vuln:product>
      <vuln:product>cpe:/a:crossnuke:nukebrowser:2.11</vuln:product>
      <vuln:product>cpe:/a:crossnuke:nukebrowser:2.20</vuln:product>
      <vuln:product>cpe:/a:crossnuke:nukebrowser:2.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1436</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006031" xml:lang="en">1006031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6731" xml:lang="en">6731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11217" xml:lang="en">nukebrowser-php-file-include(11217)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1437">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11i:v1"/>
          <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.2::i386"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1::i386"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11i"/>
          <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.2::i386"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1::i386"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1437</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp" xml:lang="en">BEA03-25.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6719" xml:lang="en">6719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11220" xml:lang="en">weblogic-keystore-plaintext-passwords(11220)</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1438">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:5.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1438</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-26.01.jsp" xml:lang="en">BEA03-26.01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6717" xml:lang="en">6717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006018" xml:lang="en">1006018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11221" xml:lang="en">weblogic-clustered-race-condition(11221)</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1439">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:silc:secure_internet_live_conferencing:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:silc:secure_internet_live_conferencing:0.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:silc:secure_internet_live_conferencing:0.9.11</vuln:product>
      <vuln:product>cpe:/a:silc:secure_internet_live_conferencing:0.9.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1439</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:49.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309775" xml:lang="en">20030201 silc question - insecure memory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309941/30/26090/threaded" xml:lang="en">20030201 Re: silc question - insecure memory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6743" xml:lang="en">6743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11244" xml:lang="en">silc-plaintext-account-information(11244)</vuln:reference>
    </vuln:references>
    <vuln:summary>Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1440">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:burton_computer_corporation:spamprobe:0.8a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:burton_computer_corporation:spamprobe:0.8a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1440</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137128" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6739" xml:lang="en">6739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006038" xml:lang="en">1006038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11247" xml:lang="en">spamprobe-newlines-href-dos(11247)</vuln:reference>
    </vuln:references>
    <vuln:summary>SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1441">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:posadis:posadis:0.50.4"/>
        <cpe-lang:fact-ref name="cpe:/a:posadis:posadis:0.50.5"/>
        <cpe-lang:fact-ref name="cpe:/a:posadis:posadis:0.50.6"/>
        <cpe-lang:fact-ref name="cpe:/a:posadis:posadis:0.50.7"/>
        <cpe-lang:fact-ref name="cpe:/a:posadis:posadis:0.50.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:posadis:posadis:0.50.4</vuln:product>
      <vuln:product>cpe:/a:posadis:posadis:0.50.5</vuln:product>
      <vuln:product>cpe:/a:posadis:posadis:0.50.6</vuln:product>
      <vuln:product>cpe:/a:posadis:posadis:0.50.7</vuln:product>
      <vuln:product>cpe:/a:posadis:posadis:0.50.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1441</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6799" xml:lang="en">6799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11285" xml:lang="en">posadis-dns-packet-dos(11285)</vuln:reference>
    </vuln:references>
    <vuln:summary>Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1442">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:ericsson:hm220dp_adsl_modem"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:ericsson:hm220dp_adsl_modem</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1442</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0127.html" xml:lang="en">20030211 Ericsson HM220dp ADSL modem Insecure Web Administration Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104619331706574&amp;w=2" xml:lang="en">20030225 RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6824" xml:lang="en">6824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11290" xml:lang="en">ericsson-hm220dp-auth-bypass(11290)</vuln:reference>
    </vuln:references>
    <vuln:summary>The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1443">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_anti-virus:4.0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_anti-virus:4.0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1443</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:11.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0130.html" xml:lang="en">20030211 SECURITY.NNOV: Kaspersky Antivirus DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11292" xml:lang="en">kav-device-name-bypass(11292)</vuln:reference>
    </vuln:references>
    <vuln:summary>Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1444">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_anti-virus:4.0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_anti-virus:4.0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1444</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0130.html" xml:lang="en">20030211 SECURITY.NNOV: Kaspersky Antivirus DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11291" xml:lang="en">kav-long-path-dos(11291)</vuln:reference>
    </vuln:references>
    <vuln:summary>Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1445">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rarlab:far_manager:1.65"/>
        <cpe-lang:fact-ref name="cpe:/a:rarlab:far_manager:1.70_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:rarlab:far_manager:1.70_beta_4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rarlab:far_manager:1.65</vuln:product>
      <vuln:product>cpe:/a:rarlab:far_manager:1.70_beta_1</vuln:product>
      <vuln:product>cpe:/a:rarlab:far_manager:1.70_beta_4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1445</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3281" xml:lang="en">3281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/311334" xml:lang="en">20030211 SECURITY.NNOV: Far buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6822" xml:lang="en">6822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11293" xml:lang="en">far-long-path-bo(11293)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1446">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rogue:rogue:5.2-2"/>
        <cpe-lang:fact-ref name="cpe:/a:rogue:rogue:985.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rogue:rogue:5.2-2</vuln:product>
      <vuln:product>cpe:/a:rogue:rogue:985.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1446</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0260.html" xml:lang="en">20030221 Rogue buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6912" xml:lang="en">6912</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11382" xml:lang="en">rogue-saveintofile-bo(11382)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the save_into_file function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1447">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:websphere_application_server:4.0.4::advanced_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:websphere_application_server:4.0.4::advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1447</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3277" xml:lang="en">3277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310118" xml:lang="en">20030204 Weak password protection in WebSphere 4.0.4 XML configuration export</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310796" xml:lang="en">20030206 Re: Weak password protection in WebSphere 4.0.4 XML configuration export</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6758" xml:lang="en">6758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11245" xml:lang="en">websphere-xml-weak-encryption(11245)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1448">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1448</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.immunitysec.com/downloads/advantages_of_block_based_analysis.html" xml:lang="en">http://www.immunitysec.com/downloads/advantages_of_block_based_analysis.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6766" xml:lang="en">6766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11274" xml:lang="en">win2k-netbios-continuation-dos(11274)</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1449">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aladdin_knowledge_systems:esafe_gateway:3.5.126.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aladdin_knowledge_systems:esafe_gateway:3.5.126.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1449</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-02/0088.html" xml:lang="en">20030206 FW-1 NG FP3 Bug - Data flow problem when transferring large files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6787" xml:lang="en">6787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11295" xml:lang="en">esafe-gateway-filter-bypass(11295)</vuln:reference>
    </vuln:references>
    <vuln:summary>Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1450">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bitchx:bitchx:1.0_c16"/>
        <cpe-lang:fact-ref name="cpe:/a:bitchx:bitchx:1.0_c19"/>
        <cpe-lang:fact-ref name="cpe:/a:bitchx:bitchx:1.0_c20cvs"/>
        <cpe-lang:fact-ref name="cpe:/a:bitchx:bitchx:75p3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bitchx:bitchx:1.0_c16</vuln:product>
      <vuln:product>cpe:/a:bitchx:bitchx:1.0_c19</vuln:product>
      <vuln:product>cpe:/a:bitchx:bitchx:1.0_c20cvs</vuln:product>
      <vuln:product>cpe:/a:bitchx:bitchx:75p3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1450</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003850.html" xml:lang="en">20030217 [argv] BitchX-353 Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3279" xml:lang="en">3279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/content/view/104622/104/" xml:lang="en">200302-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/312133" xml:lang="en">20030217 [argv] BitchX-353 Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6880" xml:lang="en">6880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11363" xml:lang="en">bitchx-irc-namreply-dos(11363)</vuln:reference>
    </vuln:references>
    <vuln:summary>BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1451">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1451</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-02/0233.html" xml:lang="en">20030219 [SNS Advisory No.61] Symantec Norton AntiVirus 2002 Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lac.co.jp/security/english/snsadv_e/61_e.html" xml:lang="en">http://www.lac.co.jp/security/english/snsadv_e/61_e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6886" xml:lang="en">6886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11365" xml:lang="en">nav-email-filename-bo(11365)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1452">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.5_fc2"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0_b14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.1</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.2</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.3</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.4</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.5</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.5_fc2</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0_b14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1452</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0047.html" xml:lang="en">20030429 [INetCop Security Advisory] Qpopper v4.0.x poppassd local root</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3268" xml:lang="en">3268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319811" xml:lang="en">20030428 Qpopper v4.0.x poppassd local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7447" xml:lang="en">7447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11877" xml:lang="en">qpopper-poppassd-root-access(11877)</vuln:reference>
    </vuln:references>
    <vuln:summary>Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1453">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xoops:xoops:1.3.5</vuln:product>
      <vuln:product>cpe:/a:xoops:xoops:1.3.6</vuln:product>
      <vuln:product>cpe:/a:xoops:xoops:1.3.7</vuln:product>
      <vuln:product>cpe:/a:xoops:xoops:1.3.8</vuln:product>
      <vuln:product>cpe:/a:xoops:xoops:1.3.9</vuln:product>
      <vuln:product>cpe:/a:xoops:xoops:2.0</vuln:product>
      <vuln:product>cpe:/a:xoops:xoops:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1453</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3269" xml:lang="en">3269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319715" xml:lang="en">20030425 XOOPS MyTextSanitizer CSS 1.3x &amp; 2.x</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7434" xml:lang="en">7434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11872" xml:lang="en">xoops-mytextsanitizer-xss(11872)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1454">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
          <cpe-lang:fact-ref name="cpe:/o:unix:unix"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.1.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:invision_power_services:invision_board:1.0</vuln:product>
      <vuln:product>cpe:/a:invision_power_services:invision_board:1.0.1</vuln:product>
      <vuln:product>cpe:/a:invision_power_services:invision_board:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1454</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3276" xml:lang="en">3276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319747" xml:lang="en">20030425 Invision Power Board Plaintext Password Disclosure Vuln</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7440" xml:lang="en">7440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11871" xml:lang="en">invision-admin-plaintext-password(11871)</vuln:reference>
    </vuln:references>
    <vuln:summary>Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1455">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b1"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b2"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b1</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b2</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1455</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=138437" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=138437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7582" xml:lang="en">7582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7590" xml:lang="en">7590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12101" xml:lang="en">poptop-launchbcrelay-pptpctrlc-bo(12101)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1456">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
          <cpe-lang:fact-ref name="cpe:/o:unix:unix"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:mike_bobbitt:album.pl:6.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mike_bobbitt:album.pl:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1456</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://perl.bobbitt.ca/yabbse/index.php?board=2;action=display;threadid=720" xml:lang="en">http://perl.bobbitt.ca/yabbse/index.php?board=2;action=display;threadid=720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3270" xml:lang="en">3270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319763" xml:lang="en">20030426 Album.pl Vulnerability - Remote Command Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7444" xml:lang="en">7444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11878" xml:lang="en">albumpl-command-execution(11878)</vuln:reference>
    </vuln:references>
    <vuln:summary>Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1457">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:auerswald:comsuite_cti_controlcenter:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:auerswald:comsuite_cti_controlcenter:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1457</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3282" xml:lang="en">3282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319946" xml:lang="en">20030429 Auerswald COMsuite/ Back Door</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7458" xml:lang="en">7458</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11923" xml:lang="en">comsuite-runasositron-backdoor-account(11923)</vuln:reference>
    </vuln:references>
    <vuln:summary>Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1458">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ttcms:ttcms:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ttcms:ttforum:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ttcms:ttcms:2.2</vuln:product>
      <vuln:product>cpe:/a:ttcms:ttforum:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1458</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3278" xml:lang="en">3278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321000" xml:lang="en">20030509 ttcms and ttforum exploits</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7543" xml:lang="en">7543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12273" xml:lang="en">ttcms-profile-sql-injection(12273)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1459">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ttcms:ttcms:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ttcms:ttforum:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ttcms:ttcms:2.2</vuln:product>
      <vuln:product>cpe:/a:ttcms:ttforum:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1459</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3278" xml:lang="en">3278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321000" xml:lang="en">20030509 ttcms and ttforum exploits</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7542" xml:lang="en">7542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12271" xml:lang="en">ttcms-ttforum-file-include(12271)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1460">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ralf_hoffmann:worker_filemanager:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.0</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.2</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.3</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.3.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.3.2</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:1.3.3</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.0</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.0.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.0.2</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.2</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.2.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.2.2</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.3</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.3.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.4</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.5</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.6</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.6.1</vuln:product>
      <vuln:product>cpe:/a:ralf_hoffmann:worker_filemanager:2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1460</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:36:59.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-11T11:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.boomerangsworld.de/worker/wchanges.php3?lang=en" xml:lang="en">http://www.boomerangsworld.de/worker/wchanges.php3?lang=en</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7460" xml:lang="en">7460</vuln:reference>
    </vuln:references>
    <vuln:summary>Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1461">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1461</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:29:19.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4897" name="oval:org.mitre.oval:def:4897"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3283" xml:lang="en">3283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320323" xml:lang="en">20030502 HP-UX 11.0 /usr/lbin/rwrite</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320371" xml:lang="en">20030503 rwrite buffer overflow in hp-ux</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7489" xml:lang="en">7489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11919" xml:lang="en">hp-rwrite-bo(11919)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument.  NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1462">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.14d"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.14e"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.15pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.15pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.15pre3"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.15pre4"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.15pre5"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_survey:mod_survey:3.0.15pre6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.7</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.14d</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.14e</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.15pre1</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.15pre2</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.15pre3</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.15pre4</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.15pre5</vuln:product>
      <vuln:product>cpe:/a:mod_survey:mod_survey:3.0.15pre6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1462</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:12.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-05/0058.html" xml:lang="en">20030504 Mod_Survey SYSBASE vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gathering.itm.mh.se/modsurvey/SA20030504.txt" xml:lang="en">http://gathering.itm.mh.se/modsurvey/SA20030504.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7498" xml:lang="en">7498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11861" xml:lang="en">modsurvey-nonexistent-survey-dos(11861)</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_survey 3.0.0 through 3.0.15-pre6 does not check whether a survey exists before creating a subdirectory for it, which allows remote attackers to cause a denial of service (disk consumption and possible crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-1463">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin:2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin:2.0.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alt-n:webadmin:2.0.0</vuln:product>
      <vuln:product>cpe:/a:alt-n:webadmin:2.0.1</vuln:product>
      <vuln:product>cpe:/a:alt-n:webadmin:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1463</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3286" xml:lang="en">3286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319735" xml:lang="en">20030425 Path disclosure and file access on WebAdmin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7438" xml:lang="en">7438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7439" xml:lang="en">7439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11874" xml:lang="en">webadmin-webadmindll-path-disclosure(11874)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11875" xml:lang="en">webadmin-webadmindll-view-files(11875)</vuln:reference>
    </vuln:references>
    <vuln:summary>Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1464">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:siemens:m45"/>
        <cpe-lang:fact-ref name="cpe:/h:siemens:s45"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:siemens:m45</vuln:product>
      <vuln:product>cpe:/h:siemens:s45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1464</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3287" xml:lang="en">3287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320555" xml:lang="en">20030506 Siemens Mobile Phone - Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7507" xml:lang="en">7507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11950" xml:lang="en">siemens-sms-image-bo(11950)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Short Message Service (SMS) message with a long image name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1465">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.1</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1465</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3288" xml:lang="en">3288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321310" xml:lang="en">20030513 Phorum Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7569" xml:lang="en">7569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12482" xml:lang="en">phorum-download-directory-traversal(12482)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in download.php in Phorum 3.4 through 3.4.2 allows remote attackers to read arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1466">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.1</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1466</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:00.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-11T12:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3288" xml:lang="en">3288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321310" xml:lang="en">20030513 Phorum Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7581" xml:lang="en">7581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7583" xml:lang="en">7583</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1467">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
          <cpe-lang:fact-ref name="cpe:/o:unix:unix:any_version"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4"/>
          <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.1</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1467</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3288" xml:lang="en">3288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321310" xml:lang="en">20030513 Phorum Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7572" xml:lang="en">7572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7573" xml:lang="en">7573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7576" xml:lang="en">7576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7577" xml:lang="en">7577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7584" xml:lang="en">7584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12487" xml:lang="en">phorum-multiple-xss(12487)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12502" xml:lang="en">phorum-register-html-injection(12502)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1468">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_final"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_beta1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_final</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc2</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1468</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321313" xml:lang="en">20030512 Re: Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7589" xml:lang="en">7589</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12436" xml:lang="en">phpnuke-weblinks-path-disclosure(12436)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1469">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:macromedia:coldfusion"/>
          <cpe-lang:fact-ref name="cpe:/a:macromedia:coldfusion:::developer"/>
          <cpe-lang:fact-ref name="cpe:/a:macromedia:coldfusion:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:macromedia:coldfusion_professional"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macromedia:coldfusion</vuln:product>
      <vuln:product>cpe:/a:macromedia:coldfusion:::developer</vuln:product>
      <vuln:product>cpe:/a:macromedia:coldfusion:6.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:coldfusion_professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1469</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3307" xml:lang="en">3307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nii.co.in/vuln/pdmac.html" xml:lang="en">http://www.nii.co.in/vuln/pdmac.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319867" xml:lang="en">20030426 NII Advisory - Path Disclosure in Cold Fusion MX Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7443" xml:lang="en">7443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11879" xml:lang="en">coldfusion-mx-path-disclosure(11879)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1470">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.7.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1470</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3296" xml:lang="en">3296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319879" xml:lang="en">20030427 MDaemon SMTP/POP/IMAP server  =>v.6.7.5: IMAP buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7446" xml:lang="en">7446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11896" xml:lang="en">mdaemon-imap-create-bo(11896)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a CREATE command with a long mailbox name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1471">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:6.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alt-n:mdaemon:6.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1471</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2003/04/msg00364.html" xml:lang="en">20030428 MDaemon SMTP/POP/IMAP server: =>6.0.7: POP remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-04/0359.html" xml:lang="en">20030428 RE: MDaemon SMTP/POP/IMAP server: =>6.0.7: POP remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11882" xml:lang="en">mdaemon-pop3-negative-dos(11882)</vuln:reference>
    </vuln:references>
    <vuln:summary>MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1472">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:3d-ftp:3d-ftp:4.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3d-ftp:3d-ftp:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1472</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3297" xml:lang="en">3297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319818" xml:lang="en">20030428 Buffer overflow in 3D-ftp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7451" xml:lang="en">7451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11883" xml:lang="en">3dftp-ftp-banner-bo(11883)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1473">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lgames:ltris:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lgames:ltris:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1473</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html" xml:lang="en">20030509 ltris-and-slashem-tty possible trouble</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321001" xml:lang="en">20030508 ltris-and-slashem-tty possible trouble</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7537" xml:lang="en">7537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11978" xml:lang="en">ltris-bo(11978)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1474">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freebsd:slashem-tty:0.0.6e.4f.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freebsd:slashem-tty:0.0.6e.4f.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1474</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:01.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-11T13:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html" xml:lang="en">20030509 ltris-and-slashem-tty possible trouble</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11979.php" xml:lang="en">slashem-tty-insecure-permissions(11979)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321001" xml:lang="en">20030508 ltris-and-slashem-tty possible trouble</vuln:reference>
    </vuln:references>
    <vuln:summary>slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1475">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netbus:netbus:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:netbus:netbus:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:netbus:netbus:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netbus:netbus:1.5</vuln:product>
      <vuln:product>cpe:/a:netbus:netbus:1.6</vuln:product>
      <vuln:product>cpe:/a:netbus:netbus:1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1475</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3289" xml:lang="en">3289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320980" xml:lang="en">20030509 Netbus 1.x exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7538" xml:lang="en">7538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11982" xml:lang="en">netbus-password-authentication-bypass(11982)</vuln:reference>
    </vuln:references>
    <vuln:summary>Netbus 1.5 through 1.7 allows more than one client to be connected at the same time, but only prompts the first connection for authentication, which allows remote attackers to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1476">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cerberus:ftp_server:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cerberus:ftp_server:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1476</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:02.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-11T15:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cerberusftp.com/cerberus-releasenotes.htm#KnownIssues" xml:lang="en">http://www.cerberusftp.com/cerberus-releasenotes.htm#KnownIssues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7556" xml:lang="en">7556</vuln:reference>
    </vuln:references>
    <vuln:summary>Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1477">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper_for_smtp:4.3.6"/>
          <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper_for_smtp:4.3.7"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper_for_smtp:4.3.6</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper_for_smtp:4.3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1477</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7562" xml:lang="en">7562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12052" xml:lang="en">mailsweeper-powerpoint-file-dos(12052)</vuln:reference>
    </vuln:references>
    <vuln:summary>MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1478">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:konqueror:3.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1478</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320266" xml:lang="en">20030502 Re: April appeared to be a month of IE bugs. Here</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7486" xml:lang="en">7486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11971" xml:lang="en">kde-konqueror-dos(11971)</vuln:reference>
    </vuln:references>
    <vuln:summary>Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1479">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:darkwet:webcam_xp:1.02.432"/>
        <cpe-lang:fact-ref name="cpe:/a:darkwet:webcam_xp:1.02.535"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:darkwet:webcam_xp:1.02.432</vuln:product>
      <vuln:product>cpe:/a:darkwet:webcam_xp:1.02.535</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1479</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3304" xml:lang="en">3304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.frame4.com/content/advisories/FSA-2003-002.txt" xml:lang="en">http://www.frame4.com/content/advisories/FSA-2003-002.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320345" xml:lang="en">20030502 Code Injection Vulnerabilities in WebcamXP Chat Feature</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7490" xml:lang="en">7490</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11952" xml:lang="en">webcamxp-multiple-xss(11952)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and 1.02.535 allows remote attackers to inject arbitrary web script or HTML via the message field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1480">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.20.32a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22.26"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22.27"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22.28"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22.29"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22.30"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.22.32"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.9"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.10"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.22"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.23"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.24"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.25"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.26"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.27"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.28"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.28:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.29"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.30"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.31"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.32"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.33"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.34"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.35"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.36"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.37"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.38"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.39"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.40"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.41"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.42"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.43"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.44"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.45"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.46"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.47"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.48"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.49"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.50"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.51"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.52"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.53a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.54a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.55"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:3.23.56"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.7:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.8:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.9:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:mysql:4.0.11:gamma"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:mysql:4.1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.20</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.20.32a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.21</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22.26</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22.27</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22.28</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22.29</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22.30</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.22.32</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.2</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.3</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.4</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.5</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.8</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.9</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.10</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.22</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.23</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.24</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.25</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.26</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.27</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.28</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.28:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.29</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.30</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.31</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.32</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.33</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.34</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.35</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.36</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.37</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.38</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.39</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.40</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.41</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.42</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.43</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.44</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.45</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.46</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.47</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.48</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.49</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.50</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.51</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.52</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.53a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.54a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.55</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:3.23.56</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.5a</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.7:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.8:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.9:gamma</vuln:product>
      <vuln:product>cpe:/a:oracle:mysql:4.0.11:gamma</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1480</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-07T12:42:10.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-11T19:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/tools/5WP031FA0U.html" xml:lang="en">http://www.securiteam.com/tools/5WP031FA0U.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7500" xml:lang="en">7500</vuln:reference>
    </vuln:references>
    <vuln:summary>MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1481">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.2_b5"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.2_b7"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.3_b1"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.3_b2"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:3.4_b3"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:4.0_b2"/>
        <cpe-lang:fact-ref name="cpe:/a:stalker:communigate_pro:4.0_b3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.1</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.2.4</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.2_b5</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.2_b7</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.3.2</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.3_b1</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.3_b2</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:3.4_b3</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:4.0.1</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:4.0.2</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:4.0.3</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:4.0.6</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:4.0_b2</vuln:product>
      <vuln:product>cpe:/a:stalker:communigate_pro:4.0_b3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1481</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3290" xml:lang="en">3290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320438" xml:lang="en">20030504 CommuniGatePro 4.0.6 [EXPLOIT]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7501" xml:lang="en">7501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11932" xml:lang="en">communigate-pro-session-hijacking(11932)</vuln:reference>
    </vuln:references>
    <vuln:summary>CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1482">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:microsoft:mn-500_wireless_base_station"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:microsoft:mn-500_wireless_base_station</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1482</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:03.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-12T13:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006691" xml:lang="en">1006691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7496" xml:lang="en">7496</vuln:reference>
    </vuln:references>
    <vuln:summary>The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1483">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:flashfxp:flashfxp:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:flashfxp:flashfxp:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1483</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/flashfxp_decrypt.c" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/flashfxp_decrypt.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006730" xml:lang="en">1006730</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7499" xml:lang="en">7499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12298" xml:lang="en">flashfxp-weak-password-encryption(12298)</vuln:reference>
    </vuln:references>
    <vuln:summary>FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1484">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1484</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3292" xml:lang="en">3292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/320544" xml:lang="en">20030505 Crash in Internet Explorer 6.0 Sp1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7502" xml:lang="en">7502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11946" xml:lang="en">ie-anchorclick-dos(11946)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1485">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.6_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.1</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.4</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.5</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.6</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.6_sp1</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1485</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:03.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-12T13:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7568" xml:lang="en">7568</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1486">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.1</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1486</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3288" xml:lang="en">3288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321310" xml:lang="en">20030513 Phorum Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7571" xml:lang="en">7571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12499" xml:lang="en">phorum-multiple-path-disclosure(12499)</vuln:reference>
    </vuln:references>
    <vuln:summary>Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1487">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.1</vuln:product>
      <vuln:product>cpe:/a:phorum:phorum:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1487</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:13.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3288" xml:lang="en">3288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321310" xml:lang="en">20030513 Phorum Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7574" xml:lang="en">7574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7578" xml:lang="en">7578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7579" xml:lang="en">7579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/12500" xml:lang="en">phorum-command-execution(12500)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1488">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:truelogik:truegalerie:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:truelogik:truegalerie:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1488</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://marc.info/?l=vulnwatch&amp;m=105128431109082&amp;w=2" xml:lang="en">20030425 True Galerie 1.0 : Admin Access &amp; File Copy</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7427" xml:lang="en">7427</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11886" xml:lang="en">truegalerie-verifadmin-admin-access(11886)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1489">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:truegalerie:truegalerie:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:truegalerie:truegalerie:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1489</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2016-10-17T22:39:45.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://marc.info/?l=vulnwatch&amp;m=105128431109082&amp;w=2" xml:lang="en">20030425 True Galerie 1.0 : Admin Access &amp; File Copy</vuln:reference>
    </vuln:references>
    <vuln:summary>upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1490">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:sonicwall:pro100:6.4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:sonicwall:pro200:6.4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:sonicwall:pro300:6.4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:sonicwall:pro100:6.4.0.1</vuln:product>
      <vuln:product>cpe:/h:sonicwall:pro200:6.4.0.1</vuln:product>
      <vuln:product>cpe:/h:sonicwall:pro300:6.4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1490</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3291" xml:lang="en">3291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319712" xml:lang="en">20030424 SonicWall Pro DoS?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7435" xml:lang="en">7435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11876" xml:lang="en">sonicwallpro-http-post-dos(11876)</vuln:reference>
    </vuln:references>
    <vuln:summary>SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1491">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall:2.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:personal_firewall:2.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1491</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/0352.html" xml:lang="en">20030422 UDP bypassing in Kerio Firewall 2.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/5FP0N1P9PI.html" xml:lang="en">http://www.securiteam.com/securitynews/5FP0N1P9PI.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7436" xml:lang="en">7436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11880" xml:lang="en">kerio-pf-firewall-bypass(11880)</vuln:reference>
    </vuln:references>
    <vuln:summary>Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1492">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:7.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:7.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1492</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319919" xml:lang="en">20030429 "netscape navigator" is cracked.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7456" xml:lang="en">7456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11924" xml:lang="en">netscape-domain-obtain-info(11924)</vuln:reference>
    </vuln:references>
    <vuln:summary>Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1493">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.1::hp_ux_10.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.1::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.1::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_10.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::nt_4.x_windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::nt_4.x_windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:5.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.1</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.1::hp_ux_10.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.1::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.1::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_10.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::nt_4.x_windows_2000</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::nt_4.x_windows_2000</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.10</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.31</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1493</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q4/0019.html" xml:lang="en">HPSBUX0310-291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8859" xml:lang="en">8859</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13467" xml:lang="en">openview-nnm-packet-dos(13467)</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (memory exhaustion) via crafted TCP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1494">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1494</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q4/0019.html" xml:lang="en">HPSBUX0310-291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8859" xml:lang="en">8859</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13467" xml:lang="en">openview-nnm-packet-dos(13467)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1495">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:insight_management_suite:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:insight_management_suite:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:insight_management_suite:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:insight_manager:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:insight_manager:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:remote_diagnostics_enabling_agent"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:insight_management_suite:3.5</vuln:product>
      <vuln:product>cpe:/a:hp:insight_management_suite:4.0</vuln:product>
      <vuln:product>cpe:/a:hp:insight_management_suite:5.0</vuln:product>
      <vuln:product>cpe:/a:hp:insight_manager:1.0</vuln:product>
      <vuln:product>cpe:/a:hp:insight_manager:1.6</vuln:product>
      <vuln:product>cpe:/a:hp:remote_diagnostics_enabling_agent</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1495</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8878" xml:lang="en">8878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13496" xml:lang="en">hp-management-gain-privileges(13496)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1496">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0f_pk8_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:4.0g_pk4_bl22"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1a_pk4_bl21"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1a_pk5_bl23"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:4.0f_pk8_bl22</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:4.0g_pk4_bl22</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1a_pk4_bl21</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1a_pk5_bl23</vuln:product>
      <vuln:product>cpe:/o:hp:tru64:5.1b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1496</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>COMPAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5973" xml:lang="en">SSRT3589</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8813" xml:lang="en">8813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13418" xml:lang="en">tru64-dtmailpr-gain-privileges(13418)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1497">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:linksys:befsx41:1.43.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:linksys:befsx41:1.43.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1497</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3298" xml:lang="en">3298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.linksys.com/download/vertxt/befsx41_1453.txt" xml:lang="en">http://www.linksys.com/download/vertxt/befsx41_1453.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341309" xml:lang="en">20031015 LinkSys EtherFast Router Denial of Service Attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8834" xml:lang="en">8834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13436" xml:lang="en">linksys-etherfast-logpagenum-dos(13436)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the system log viewer of Linksys BEFSX41 1.44.3 allows remote attackers to cause a denial of service via an HTTP request with a long Log_Page_Num variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1498">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wrensoft:zoom_search_engine:2.0_build_1018"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wrensoft:zoom_search_engine:2.0_build_1018</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1498</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0173.html" xml:lang="en">20031014 Cross-Site Scripting Vulnerability in Wrensoft Zoom Search Engine</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8823" xml:lang="en">8823</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13431" xml:lang="en">zoom-search-xss(13431)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1499">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bytehoard:bytehoard:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bytehoard:bytehoard:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1499</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-10/0200.html" xml:lang="en">20031019 ByteHoard Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012430.html" xml:lang="en">20031019 ByteHoard Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/6L00L008KE.html" xml:lang="en">http://www.securiteam.com/unixfocus/6L00L008KE.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8850" xml:lang="en">8850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13456" xml:lang="en">bytehoard-dotdot-directory-traversal(13456)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1500">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cpcommerce:cpcommerce:0.5f"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cpcommerce:cpcommerce:0.5f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1500</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cpcommerce.org/forums/index.php?board=2;action=display;threadid=864" xml:lang="en">http://cpcommerce.org/forums/index.php?board=2;action=display;threadid=864</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3301" xml:lang="en">3301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/6H00E2K8KG.html" xml:lang="en">http://www.securiteam.com/unixfocus/6H00E2K8KG.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341757" xml:lang="en">20031019 ZH2003-31SA (security advisory): file inclusion vulnerability in cpCommerce</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8851" xml:lang="en">8851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13457" xml:lang="en">cpCommerce-functionsphp-file-include(13457)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1501">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gast_arbeiter:gast_arbeiter:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gast_arbeiter:gast_arbeiter:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1501</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341870" xml:lang="en">20031020 Gast Arbeiter Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8858" xml:lang="en">8858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13469" xml:lang="en">gast-arbeiter-file-upload(13469)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1502">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snert.com:mod_throttle:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snert.com:mod_throttle:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1502</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:06.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-12T15:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012043.html" xml:lang="en">20031015 Mod-Throttle [was: client attacks server - XSS]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8822" xml:lang="en">8822</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1503">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aol:instant_messenger:5.2.3292"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aol:instant_messenger:5.2.3292</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1503</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0059.html" xml:lang="en">20031015 Buffer Overflow in AOL Instant Messager</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8825" xml:lang="en">8825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13443" xml:lang="en">aim-getfile-screenname-bo(13443)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1504">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:goldscripts:goldlink:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:goldscripts:goldlink:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1504</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3302" xml:lang="en">3302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341760" xml:lang="en">20031018 Get admin level on Goldlink script v3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8847" xml:lang="en">8847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13465" xml:lang="en">goldlink-variables-gain-access(13465)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1505">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1505</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3295" xml:lang="en">3295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342010" xml:lang="en">20031022 IE6 CSS-Crash</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8874" xml:lang="en">8874</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13809" xml:lang="en">ie-scrollbarbasecolor-dos(13809)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1506">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:daniel_barron:dansguardian:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:daniel_barron:dansguardian:3.1_r5"/>
        <cpe-lang:fact-ref name="cpe:/a:daniel_barron:dansguardian:3.1_r6"/>
        <cpe-lang:fact-ref name="cpe:/a:daniel_barron:dansguardian:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:daniel_barron:dansguardian:3.0</vuln:product>
      <vuln:product>cpe:/a:daniel_barron:dansguardian:3.1_r5</vuln:product>
      <vuln:product>cpe:/a:daniel_barron:dansguardian:3.1_r6</vuln:product>
      <vuln:product>cpe:/a:daniel_barron:dansguardian:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1506</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:14.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3299" xml:lang="en">3299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342160" xml:lang="en">20031022 CensorNet: Cross Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342551" xml:lang="en">20031027 Re: CensorNet: Cross Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342577" xml:lang="en">20031027 Re: CensorNet: Cross Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8876" xml:lang="en">8876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13507" xml:lang="en">censornet-cgi-xss(13507)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1507">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:planet_technology_corp:wgsd-1020"/>
        <cpe-lang:fact-ref name="cpe:/h:planet_technology_corp:wsw-2401"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:planet_technology_corp:wgsd-1020</vuln:product>
      <vuln:product>cpe:/h:planet_technology_corp:wsw-2401</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1507</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007924" xml:lang="en">1007924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341329" xml:lang="en">20031015 Few issues previously unpublished in English</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8837" xml:lang="en">8837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13446" xml:lang="en">wgsd-default-admin-account(13446)</vuln:reference>
    </vuln:references>
    <vuln:summary>Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1508">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mirc:mirc:6.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirc:mirc:6.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1508</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:07.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-14T13:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3303" xml:lang="en">3303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.irchelp.org/irchelp/mirc/exploit.html" xml:lang="en">http://www.irchelp.org/irchelp/mirc/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/342179" xml:lang="en">20031023 (Fw) : mIRC 6.12 (latest) DCC Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8880" xml:lang="en">8880</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1509">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.818"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.830"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.841"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.853"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.818</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.830</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.841</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.853</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1509</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-08-16T21:29:00.880-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/securityupdate_october2003.html" xml:lang="en">http://service.real.com/help/faq/security/securityupdate_october2003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8839" xml:lang="en">8839</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13445" xml:lang="en">realoneplayer-temporary-script-execution(13445)</vuln:reference>
    </vuln:references>
    <vuln:summary>Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1510">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rit_research_labs:tinyweb:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rit_research_labs:tinyweb:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1510</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6S0052K8LQ.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6S0052K8LQ.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8810" xml:lang="en">8810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13402" xml:lang="en">tinyweb-httpget-dos(13402)</vuln:reference>
    </vuln:references>
    <vuln:summary>TinyWeb 1.9 allows remote attackers to cause a denial of service (CPU consumption) via a ".%00." in an HTTP GET request to the cgi-bin directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1511">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:d"/>
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:zxc"/>
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:zxe"/>
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:zxe1"/>
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:zxv4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95</vuln:product>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:d</vuln:product>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:zxc</vuln:product>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:zxe</vuln:product>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:zxe1</vuln:product>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:zxv4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1511</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:07.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-14T13:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3306" xml:lang="en">3306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.geocities.com/gzhangx/websrv/docs/security.html" xml:lang="en">http://www.geocities.com/gzhangx/websrv/docs/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341452" xml:lang="en">20031016 CSS Vulnerability in Bajie HTTP JServer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8841" xml:lang="en">8841</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1512">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:khaled_mardam-bey:mirc:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:khaled_mardam-bey:mirc:6.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:khaled_mardam-bey:mirc:6.1</vuln:product>
      <vuln:product>cpe:/a:khaled_mardam-bey:mirc:6.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1512</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:07.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-14T13:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8818" xml:lang="en">8818</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1513">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:caucho_technology:resin:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:caucho_technology:resin:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:caucho_technology:resin:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:caucho_technology:resin:2.1.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:caucho_technology:resin:2.0</vuln:product>
      <vuln:product>cpe:/a:caucho_technology:resin:2.1.1</vuln:product>
      <vuln:product>cpe:/a:caucho_technology:resin:2.1.2</vuln:product>
      <vuln:product>cpe:/a:caucho_technology:resin:2.1.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1513</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012361.html" xml:lang="en">20031019 Caucho Resin 2.x - Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8852" xml:lang="en">8852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13460" xml:lang="en">resin-name-comment-xss(13460)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1514">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:emule:emule:0.29c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:emule:emule:0.29c</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1514</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3294" xml:lang="en">3294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341754" xml:lang="en">20031019 eMule 2.2 [0.29c] - Web Control Panel - DOS(Denial Of Service)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8854" xml:lang="en">8854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13464" xml:lang="en">emule-long-password-dos(13464)</vuln:reference>
    </vuln:references>
    <vuln:summary>eMule 0.29c allows remote attackers to cause a denial of service (crash) via a long password, possibly due to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1515">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:origo:asr-8100:adsl_router_3.21"/>
        <cpe-lang:fact-ref name="cpe:/h:origo:asr-8400:adsl_router"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:origo:asr-8100:adsl_router_3.21</vuln:product>
      <vuln:product>cpe:/h:origo:asr-8400:adsl_router</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1515</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3300" xml:lang="en">3300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341752" xml:lang="en">20031012 Origo ASR-8100 ADSL router remote factory reset</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8855" xml:lang="en">8855</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13463" xml:lang="en">origo-default-settings-restore(13463)</vuln:reference>
    </vuln:references>
    <vuln:summary>Origo ASR-8100 ADSL Router 3.21 has an administration service running on port 254 that does not require a password, which allows remote attackers to cause a denial of service by restoring the factory defaults.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1516">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:java_plug-in:1.4.2_01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java_plug-in:1.4.2_01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1516</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:08.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-14T15:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341815" xml:lang="en">20031020 Cross Site Java applets</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8857" xml:lang="en">8857</vuln:reference>
    </vuln:references>
    <vuln:summary>The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1517">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dansie:shopping_cart"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dansie:shopping_cart</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1517</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/6T00T008KG.html" xml:lang="en">http://www.securiteam.com/securitynews/6T00T008KG.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8860" xml:lang="en">8860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13461" xml:lang="en">dansie-cartpl-path-disclosure(13461)</vuln:reference>
    </vuln:references>
    <vuln:summary>cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1518">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adiscon:winsyslog:4.21_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:adiscon:winsyslog:5.0_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adiscon:winsyslog:4.21_sp1</vuln:product>
      <vuln:product>cpe:/a:adiscon:winsyslog:5.0_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1518</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adiscon.com/Common/en/advisory/2003-09-15.asp" xml:lang="en">http://www.adiscon.com/Common/en/advisory/2003-09-15.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6L00F158KE.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6L00F158KE.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8821" xml:lang="en">8821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13428" xml:lang="en">winsyslog-long-syslog-dos(13428)</vuln:reference>
    </vuln:references>
    <vuln:summary>Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1519">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vivisimo:clustering_engine:0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vivisimo:clustering_engine:0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1519</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007955" xml:lang="en">1007955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8862" xml:lang="en">8862</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13452" xml:lang="en">vívísimo-clustering-engine-xss(13452)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1520">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fuzzymonkey:myclassifieds:2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fuzzymonkey:myclassifieds:2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1520</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:09.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-14T16:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3293" xml:lang="en">3293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341908" xml:lang="en">20031021 SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8863" xml:lang="en">8863</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1521">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:java_plug-in:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_plug-in:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_plug-in:1.4.2_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_plug-in:1.4.2_02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java_plug-in:1.4</vuln:product>
      <vuln:product>cpe:/a:sun:java_plug-in:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:java_plug-in:1.4.2_01</vuln:product>
      <vuln:product>cpe:/a:sun:java_plug-in:1.4.2_02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1521</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:09.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-17T18:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341943" xml:lang="en">20031021 IE6 &amp; Java 1.4.2_02 applet: Hardware stress on floppy drive</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8867" xml:lang="en">8867</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1522">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pscs:vpop3_web_mail_server:2.0e"/>
        <cpe-lang:fact-ref name="cpe:/a:pscs:vpop3_web_mail_server:2.0f"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pscs:vpop3_web_mail_server:2.0e</vuln:product>
      <vuln:product>cpe:/a:pscs:vpop3_web_mail_server:2.0f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1522</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pscs.co.uk/products/vpop3/whatsnew.html" xml:lang="en">http://www.pscs.co.uk/products/vpop3/whatsnew.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6S00S008KW.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6S00S008KW.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8869" xml:lang="en">8869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13459" xml:lang="en">vpop3-login-xss(13459)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1523">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dbmail:dbmail:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dbmail:dbmail:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dbmail:dbmail:1.0</vuln:product>
      <vuln:product>cpe:/a:dbmail:dbmail:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1523</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8829" xml:lang="en">8829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13416" xml:lang="en">dbmail-multiple-sql-injection(13416)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1524">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pgpi:pgpdisk:6.0.2i"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pgpi:pgpdisk:6.0.2i</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1524</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/windowsntfocus/6M00L0K8KI.html" xml:lang="en">http://www.securiteam.com/windowsntfocus/6M00L0K8KI.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8870" xml:lang="en">8870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13490" xml:lang="en">pgpdisk-obtain-information(13490)</vuln:reference>
    </vuln:references>
    <vuln:summary>PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1525">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:my_photo_gallery:my_photo_gallery:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:my_photo_gallery:my_photo_gallery:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1525</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8872" xml:lang="en">8872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/13498" xml:lang="en">myphotogallery-unknown-vulnerabilities(13498)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1526">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1526</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:10.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-18T11:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/341743" xml:lang="en">20031018 PHP-Nuke Path Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8848" xml:lang="en">8848</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1527">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:internet_security_systems_blackice_defender:2.9cap"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:blackice_server_protection:3.5.cdf"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:internet_security_systems_blackice_defender:2.9cap</vuln:product>
      <vuln:product>cpe:/a:iss:blackice_server_protection:3.5.cdf</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1527</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:10.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-18T12:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://online.securityfocus.com/archive/1/294411" xml:lang="en">20021008 Multiple Vendor PC firewall remote denial of services Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10314.php" xml:lang="en">firewall-autoblock-spoofing-dos(10314)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5917" xml:lang="en">5917</vuln:reference>
    </vuln:references>
    <vuln:summary>BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1528">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fujitsu:siemens_networker:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fujitsu:siemens_networker:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1528</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:49.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3353" xml:lang="en">3353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/350237/30/21640/threaded" xml:lang="en">20040119 Networker 6.0 - possible symlink attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9446" xml:lang="en">9446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008801" xml:lang="en">1008801</vuln:reference>
    </vuln:references>
    <vuln:summary>nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1529">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:seagull_software_systems:j_walk_application_server:3.2c9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:seagull_software_systems:j_walk_application_server:3.2c9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1529</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0357.html" xml:lang="en">20030325 IRM 005: JWalk Application Server Version 3.2c9 Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7160" xml:lang="en">7160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006378" xml:lang="en">1006378</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11623" xml:lang="en">jwalk-dotdot-directory-traversal(11623)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1530">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb:phpbb:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb:phpbb:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1530</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:50.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html" xml:lang="en">20030116 phpBB SQL Injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/307212/30/26300/threaded" xml:lang="en">20030117 phpBB SQL Injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6634" xml:lang="en">6634</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1531">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lilikoi:ceilidh:2.70"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lilikoi:ceilidh:2.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1531</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104878375423320&amp;w=2" xml:lang="en">20030327 [SCSA-013] Cross Site Scripting vulnerability in testcgi.exe</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7214" xml:lang="en">7214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006391" xml:lang="en">1006391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11638" xml:lang="en">ceilidh-textcgi-xss(11638)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1532">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:julien_desaunay:phpmyshop:1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:julien_desaunay:phpmyshop:1.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1532</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:50.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3348" xml:lang="en">3348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309921/30/26090/threaded" xml:lang="en">20030203 phpMyShop (php)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6746" xml:lang="en">6746</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006030" xml:lang="en">1006030</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1533">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phppass:phppass:2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phppass:phppass:2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1533</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:50.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3349" xml:lang="en">3349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/307224/30/26300/threaded" xml:lang="en">20030113 phpPass (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6594" xml:lang="en">6594</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005948" xml:lang="en">1005948</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1534">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:justice_media:guestbook:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:justice_media:guestbook:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1534</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:51.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3347" xml:lang="en">3347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316745/30/25280/threaded" xml:lang="en">20030329 Justice Guestbook 1.3 vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7233" xml:lang="en">7233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006412" xml:lang="en">1006412</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1535">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:justice_media:guestbook:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:justice_media:guestbook:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1535</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:51.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3347" xml:lang="en">3347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316745/30/25280/threaded" xml:lang="en">20030329 Justice Guestbook 1.3 vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7234" xml:lang="en">7234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006412" xml:lang="en">1006412</vuln:reference>
    </vuln:references>
    <vuln:summary>Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1536">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dcp-portal:dcp-portal:5.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dcp-portal:dcp-portal:5.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1536</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:15.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html" xml:lang="en">20030318 Some XSS vulns</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7141" xml:lang="en">7141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7144" xml:lang="en">7144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11602" xml:lang="en">dcpportal-search-calendar-xss(11602)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1537">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.723"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.723</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1537</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:11.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-18T14:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0117.html" xml:lang="en">20030309 Postnuke v 0.723 SQL injection and directory traversing</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1538">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:suse:suse_linux_openexchange_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:office_server"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:suse:suse_linux_openexchange_server:4.0</vuln:product>
      <vuln:product>cpe:/o:suse:office_server</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1538</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:11.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-21T11:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_005_susehelp.html" xml:lang="en">SUSE-SA:2003:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005954" xml:lang="en">1005954</vuln:reference>
    </vuln:references>
    <vuln:summary>susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1539">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:onedotoh:simple_file_manager:0.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:onedotoh:simple_file_manager:0.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1539</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:11.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=144274" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=144274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=695597&amp;group_id=60333&amp;atid=493842" xml:lang="en">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=695597&amp;group_id=60333&amp;atid=493842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7035" xml:lang="en">7035</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1540">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wfchat:wfchat:1.0:beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wfchat:wfchat:1.0:beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1540</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:51.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3645" xml:lang="en">3645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006352" xml:lang="en">1006352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315583/30/25430/threaded" xml:lang="en">20030319 WF-Chat</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7147" xml:lang="en">7147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11571" xml:lang="en">wf-chat-plaintext-passwords(11571)</vuln:reference>
    </vuln:references>
    <vuln:summary>WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1541">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:planetmoon:guestbook:tr3.a.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:planetmoon:guestbook:tr3.a.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1541</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:52.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3653" xml:lang="en">3653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315895/30/25400/threaded" xml:lang="en">20030321 Guestbook tr3.a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7167" xml:lang="en">7167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006360" xml:lang="en">1006360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11609" xml:lang="en">guestbooktr3a-plaintext-password-disclosure(11609)</vuln:reference>
    </vuln:references>
    <vuln:summary>PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1542">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ondrej_jombik:phpwebfilemanager:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ondrej_jombik:phpwebfilemanager:0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1542</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:12.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-14T14:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://platon.sk/projects/release_view_page.php?release_id=2" xml:lang="en">http://platon.sk/projects/release_view_page.php?release_id=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6933" xml:lang="en">6933</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1543">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:zxc"/>
        <cpe-lang:fact-ref name="cpe:/a:bajie:java_http_server:0.95:zxe"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:zxc</vuln:product>
      <vuln:product>cpe:/a:bajie:java_http_server:0.95:zxe</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1543</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-08-07T21:29:00.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006428" xml:lang="en">1006428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.geocities.com/gzhangx/websrv/docs/security.html" xml:lang="en">http://www.geocities.com/gzhangx/websrv/docs/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lucaercoli.it/advs/bajie.txt" xml:lang="en">http://www.lucaercoli.it/advs/bajie.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/5LP10009FC.html" xml:lang="en">http://www.securiteam.com/securitynews/5LP10009FC.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7344" xml:lang="en">7344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11687" xml:lang="en">bajie-error-message-xss(11687)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1544">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:adv_srv"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:srv"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:adv_srv</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:srv</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1544</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-08-07T21:29:00.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3654" xml:lang="en">3654</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/kb/815225/en-us" xml:lang="en">815225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308059" xml:lang="en">20030123 DoS attack on Windows 2000 Terminal Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/308164" xml:lang="en">20030124 RE: DoS attack on Windows 2000 Terminal Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6672" xml:lang="en">6672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005986" xml:lang="en">1005986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11141" xml:lang="en">win2k-terminal-msgina-dos(11141)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11816" xml:lang="en">win2k-terminal-msgina-permissions(11816)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1545">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nukestyles:viewpage"/>
        <cpe-lang:fact-ref name="cpe:/a:phpnuke:nukestyles_viewpage_module"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nukestyles:viewpage</vuln:product>
      <vuln:product>cpe:/a:phpnuke:nukestyles_viewpage_module</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1545</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:52.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316179/30/25340/threaded" xml:lang="en">20030325 PHPNuke viewpage.php allows Remote File retrieving</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316198/30/25340/threaded" xml:lang="en">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316209/30/25340/threaded" xml:lang="en">20030325 Re: PHPNuke viewpage.php and another SQL injections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316233/30/25340/threaded" xml:lang="en">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316327/30/25340/threaded" xml:lang="en">20030326 Re: PHPNuke viewpage.php allows Remote File retrieving</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316341/30/25310/threaded" xml:lang="en">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316585/30/25310/threaded" xml:lang="en">20030327 Re: PHPNuke viewpage.php allows Remote File retrieving</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7191" xml:lang="en">7191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006377" xml:lang="en">1006377</vuln:reference>
    </vuln:references>
    <vuln:summary>Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter.  NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1546">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:filebased:guestbook:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:filebased:guestbook:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1546</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-08-07T21:29:00.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-03/0219.html" xml:lang="en">20030314 Guestbook v1.1.3 CSS Vuln</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7104" xml:lang="en">7104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006289" xml:lang="en">1006289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11540" xml:lang="en">filebased-guestbook-gbook-xss(11540)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1547">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_beta1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc1</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc2</vuln:product>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1547</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:53.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3718" xml:lang="en">3718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316925/30/25250/threaded" xml:lang="en">20030331 PHP-Nuke block-Forums.php subject vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317230/30/25220/threaded" xml:lang="en">20030401 Re: PHP-Nuke block-Forums.php subject vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7248" xml:lang="en">7248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11675" xml:lang="en">phpnuke-blockforums-subject-xss(11675)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1548">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:myabracadaweb:myabracadaweb:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myabracadaweb:myabracadaweb:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1548</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:53.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3717" xml:lang="en">3717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315317/30/25460/threaded" xml:lang="en">20030317 [SCSA-010] Path Disclosure &amp; Cross Site Scripting Vulnerability in MyABraCaDaWeb</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7126" xml:lang="en">7126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006308" xml:lang="en">1006308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11556" xml:lang="en">myabracadaweb-index-path-disclosure(11556)</vuln:reference>
    </vuln:references>
    <vuln:summary>MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1549">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:myabracadaweb:myabracadaweb:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myabracadaweb:myabracadaweb:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1549</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:54.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3717" xml:lang="en">3717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315317/30/25460/threaded" xml:lang="en">20030317 [SCSA-010] Path Disclosure &amp; Cross Site Scripting Vulnerability in MyABraCaDaWeb</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7127" xml:lang="en">7127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006308" xml:lang="en">1006308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11557" xml:lang="en">myabracadaweb-index-makw-xss(11557)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1550">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xoops:xoops:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1550</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-08-07T21:29:00.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104820295115420&amp;w=2" xml:lang="en">20030320 [SCSA-011] Path Disclosure Vulnerability in XOOPS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104887510828106&amp;w=2" xml:lang="en">20030328 Re: [SCSA-011] Path Disclosure Vulnerability in XOOPS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7149" xml:lang="en">7149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11587" xml:lang="en">xoops-xoopsoption-path-disclosure(11587)</vuln:reference>
    </vuln:references>
    <vuln:summary>XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1551">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.0_sp3:revision_e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:groupwise:6.0_sp3:revision_e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1551</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-08-07T21:29:00.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6896" xml:lang="en">6896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006171" xml:lang="en">1006171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11394" xml:lang="en">groupwise-script-execution(11394)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."</vuln:summary>
  </entry>
  <entry id="CVE-2003-1552">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:graeme:uploader:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:graeme:uploader:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1552</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:54.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313787/30/25670/threaded" xml:lang="en">20030304 uploader.php vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313819/30/25640/threaded" xml:lang="en">20030304 uploader.php script</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11467" xml:lang="en">uploader-uploads-file-upload(11467)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1553">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sips:sips:0.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sips:sips:0.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1553</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:54.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3780" xml:lang="en">3780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315504/30/25460/threaded" xml:lang="en">20030318 SIPS (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7134" xml:lang="en">7134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11572" xml:lang="en">sips-user-obtain-information(11572)</vuln:reference>
    </vuln:references>
    <vuln:summary>Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1554">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scoznet:scozbook:1.1_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scoznet:scozbook:1.1_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1554</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:55.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3781" xml:lang="en">3781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316747/30/25280/threaded" xml:lang="en">20030329 ScozBook BETA 1.1 vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7235" xml:lang="en">7235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006413" xml:lang="en">1006413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11658" xml:lang="en">scozbook-add-xss(11658)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1555">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scoznet:scozbook:1.1_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scoznet:scozbook:1.1_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1555</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:55.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3781" xml:lang="en">3781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316747/30/25280/threaded" xml:lang="en">20030329 ScozBook BETA 1.1 vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7236" xml:lang="en">7236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006413" xml:lang="en">1006413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11659" xml:lang="en">scozbook-view-path-disclosure(11659)</vuln:reference>
    </vuln:references>
    <vuln:summary>ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1556">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cgi_city:cc_guestbook"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cgi_city:cc_guestbook</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1556</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:56.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3796" xml:lang="en">3796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316764/30/25250/threaded" xml:lang="en">20030329 CGI-City's CCGuestBook Script Injection Vulns</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7237" xml:lang="en">7237</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1557">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:spamassassin:spamassassin:2.40"/>
        <cpe-lang:fact-ref name="cpe:/a:spamassassin:spamassassin:2.41"/>
        <cpe-lang:fact-ref name="cpe:/a:spamassassin:spamassassin:2.42"/>
        <cpe-lang:fact-ref name="cpe:/a:spamassassin:spamassassin:2.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spamassassin:spamassassin:2.40</vuln:product>
      <vuln:product>cpe:/a:spamassassin:spamassassin:2.41</vuln:product>
      <vuln:product>cpe:/a:spamassassin:spamassassin:2.42</vuln:product>
      <vuln:product>cpe:/a:spamassassin:spamassassin:2.43</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1557</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:56.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=104342896818777&amp;w=2" xml:lang="en">20030123 SpamAssassin / spamc+BSMTP remote buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/309912/30/26090/threaded" xml:lang="en">GLSA-200302-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/310212/30/26030/threaded" xml:lang="en">20030204 Re: GLSA: Mail-SpamAssasin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6679" xml:lang="en">6679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11154" xml:lang="en">spamassassin-spamc-offbyone-bo(11154)</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1558">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fefe:fnord:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fefe:fnord:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1558</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T11:29:56.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.fefe.de/fnord/" xml:lang="en">http://www.fefe.de/fnord/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/307400/30/26270/threaded" xml:lang="en">20030117 GLSA: fnord</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6635" xml:lang="en">6635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/11121" xml:lang="en">fnord-httpdc-cgi-bo(11121)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in httpd.c of fnord 1.6 allows remote attackers to create a denial of service (crash) and possibly execute arbitrary code via a long CGI request passed to the do_cgi function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1559">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.22"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.22</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1559</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T00:28:34.390-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3989" xml:lang="en">3989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html" xml:lang="en">http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348360" xml:lang="en">20031224 IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348574" xml:lang="en">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9295" xml:lang="en">9295</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1560">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:navigator:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1560</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T00:28:34.530-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4004" xml:lang="en">4004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348574" xml:lang="en">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</vuln:reference>
    </vuln:references>
    <vuln:summary>Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1561">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera:opera"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera:opera</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-1561</vuln:cve-id>
    <vuln:published-datetime>2003-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T00:28:34.717-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4004" xml:lang="en">4004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/348574" xml:lang="en">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</vuln:reference>
    </vuln:references>
    <vuln:summary>Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-1562">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.9.9p2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.9p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:2.9p2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.2p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2.2p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2.3p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.3p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.4p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.5p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6.1p2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:1.2</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.2.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.2.2</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.2.3</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.2.27</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.3</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.5</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.5.7</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:1.5.8</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:2</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:2.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:2.1.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:2.2</vuln:product>
      <vuln:product>cpe:/a:openbsd:opens